Skip to content

Security: Chaptarr/chaptarr

SECURITY.md

Security Policy

🔒 Reporting Security Vulnerabilities

The Chaptarr team takes security seriously. We appreciate your efforts to responsibly disclose your findings.

How to Report

If you discover a security vulnerability, please:

  1. DO NOT create a public GitHub issue
  2. Use Report a vulnerability on the repository's Security tab (preferred) OR email team@chaptarr.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes

What to Expect

  • Acknowledgment: We'll make a best effort to acknowledge receipt within 48 hours
  • Assessment: We'll assess the vulnerability and its impact
  • Fix Timeline: We'll provide an estimated timeline for a fix
  • Credit: We'll credit you in the release notes (unless you prefer to remain anonymous)

Scope

This security policy applies to:

  • The Chaptarr application itself
  • Official Docker images
  • Configuration that could lead to security issues

Out of Scope

  • Modified builds or forks
  • Upstream dependency issues with no impact through Chaptarr (if a dependency flaw is exploitable through Chaptarr or its official image, report it to us and we'll coordinate with upstream)
  • Social engineering attacks

Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Give us reasonable time to fix issues before disclosure

Thank you for helping keep Chaptarr and its users safe!

There aren't any published security advisories