Security fixes are applied to the latest released image and the nightly
branch. Older releases may receive no security updates.
Please do not report vulnerabilities in public issues or discussions. Use the repository's Security tab and Report a vulnerability to submit a private report, including affected versions, reproduction steps, and any known impact. If private reporting is unavailable, open a public issue requesting a private contact without including technical details.
We aim to acknowledge reports within 7 days, provide progress updates while investigating, and coordinate disclosure after a fix is available.
Reports are welcome for the SuggestArr application, its official Docker image, and repository-managed CI workflows. Do not include real API keys, passwords, cookies, tokens, or private media data in a report.