The Chaptarr team takes security seriously. We appreciate your efforts to responsibly disclose your findings.
If you discover a security vulnerability, please:
- DO NOT create a public GitHub issue
- Use Report a vulnerability on the repository's Security tab (preferred) OR email team@chaptarr.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes
- Acknowledgment: We'll make a best effort to acknowledge receipt within 48 hours
- Assessment: We'll assess the vulnerability and its impact
- Fix Timeline: We'll provide an estimated timeline for a fix
- Credit: We'll credit you in the release notes (unless you prefer to remain anonymous)
This security policy applies to:
- The Chaptarr application itself
- Official Docker images
- Configuration that could lead to security issues
- Modified builds or forks
- Upstream dependency issues with no impact through Chaptarr (if a dependency flaw is exploitable through Chaptarr or its official image, report it to us and we'll coordinate with upstream)
- Social engineering attacks
We will not pursue legal action against security researchers who:
- Act in good faith
- Avoid privacy violations and data destruction
- Give us reasonable time to fix issues before disclosure
Thank you for helping keep Chaptarr and its users safe!