If you discover a security vulnerability in Digarr, please report it privately. Do not open a public issue.
Use GitHub's built-in private vulnerability reporting to submit a report. This keeps the details confidential until a fix is available.
Reach out to @iuliandita via GitHub.
- Acknowledgment within 48 hours
- Status update within 7 days
- Fix and disclosure coordinated with you before any public announcement
This policy covers the Digarr application code, Docker images, and Helm charts in this repository. It does not cover third-party services Digarr integrates with (Lidarr, Spotify, Deezer, MusicBrainz, etc.).
Only the latest release is supported with security fixes. We recommend always running the most recent version.