Security fixes target the latest stable release. Older releases receive no backports. Check whether an issue persists after upgrading.
Use GitHub's vulnerability reporting form. Keep vulnerability details out of public issues, discussions, and pull requests.
Include the affected version or commit, reproduction steps, expected and observed behaviour, potential impact, relevant deployment details, and redacted logs or screenshots where available. Remove credentials, session cookies, tokens, and personal data. Test only systems you own or have permission to assess.
Use the private report to coordinate fixes and disclosure. Coordinate public disclosure with the maintainer until a fix or mitigation is available. Response and fix times are not guaranteed.
Report vulnerabilities in Disco, its images, and its Seerr integration here. For issues confined to an upstream project, follow that project's reporting process. If the source is unclear, report privately here and describe what you observed.