ChaptarrNG is Snapetech's maintained fork of Chaptarr. This policy covers this repository, the ChaptarrNG Docker image, and the project's packaging and release workflows.
Do not report vulnerabilities in a public issue. Use Report a vulnerability
on this repository's Security tab. If that option is unavailable, email
seerrng@proton.me with a description, reproduction steps, and potential
impact. Do not include private user data.
The maintainers will review the report and coordinate a fix and disclosure with the reporter. Upstream-only issues that do not affect ChaptarrNG should be reported to the upstream project. Dependency vulnerabilities that can be exploited through ChaptarrNG or its image are in scope here.
Security research conducted in good faith, without accessing or destroying another person's data, is welcome. Give the maintainers reasonable time to address a confirmed issue before public disclosure.