SyncTV is currently developed on the main branch. Until stable release branches are published, security fixes target the current main branch and the latest published release, if one exists.
- Provider credentials, media proxying, request header handling, and SSRF-related behavior.
- HTTP, gRPC, WebSocket, management, metrics, and cluster control surfaces.
- Docker Compose, Helm, Kubernetes Ingress, and default deployment hardening.
- Protobuf/API design issues that can lead to privilege escalation, data exposure, or denial of service.
## Disclosure Expectations
Give maintainers reasonable time to investigate, patch, and publish guidance before public disclosure. Avoid sharing exploit code or live-service targets unless maintainers explicitly request controlled reproduction details.
If a report includes accidental secrets, assume they are compromised. Rotate JWT secrets, OPAQUE setup secrets, provider tokens, OAuth2 client secrets, SMTP passwords, management tokens, and credential encryption keys according to the blast radius.