| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in easiarr, please report it responsibly:
- DO NOT create a public GitHub issue for security vulnerabilities
- Email security concerns to: info[at]muhammedaksam.com.tr
- Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Target: Within 30 days for critical issues
easiarr stores sensitive information in .env files. Always:
- Never commit
.envfiles to version control - Set restrictive file permissions:
chmod 600 $XDG_CONFIG_HOME/easiarr/.env - Use strong, unique passwords for each service
- Regularly rotate API keys and credentials
- Use Traefik with HTTPS when exposing services externally
- Consider using Cloudflare Tunnel for secure external access
- Enable authentication on all services (Global username/password)
- Use Cloudflare Access for additional protection when available
- Keep Docker and container images updated
- Use the provided PUID/PGID settings to run containers as non-root
- Limit container capabilities where possible
- Mount volumes with minimal required permissions
This security policy applies to:
- The easiarr npm package (@muhammedaksam/easiarr)
- Generated docker-compose.yml configurations
- Generated .env files and API keys
- The easiarr TUI application
- Third-party applications configured by easiarr (Radarr, Sonarr, etc.)
- Docker/Bun runtime vulnerabilities
- User misconfiguration after initial setup