# Security Policy ## Reporting a Vulnerability If you discover a security vulnerability in Digarr, please report it privately. **Do not open a public issue.** ### Preferred: GitHub Private Vulnerability Reporting Use GitHub's built-in [private vulnerability reporting](https://github.com/iuliandita/digarr/security/advisories/new) to submit a report. This keeps the details confidential until a fix is available. ### Alternative: Direct Contact Reach out to [@iuliandita](https://github.com/iuliandita) via GitHub. ## What to Expect - Acknowledgment within 48 hours - Status update within 7 days - Fix and disclosure coordinated with you before any public announcement ## Scope This policy covers the Digarr application code, Docker images, and Helm charts in this repository. It does not cover third-party services Digarr integrates with (Lidarr, Spotify, Deezer, MusicBrainz, etc.). ## Supported Versions Only the latest release is supported with security fixes. We recommend always running the most recent version.