Skip to content

Security: frankieramirez/comicarr

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Comicarr, please report it responsibly:

  1. Do not open a public GitHub issue for a security vulnerability.
  2. Use GitHub's private vulnerability reporting:
    • Go to the Security tab and click "Report a vulnerability".
  3. Include as much detail as possible: steps to reproduce, affected versions, and potential impact

You should receive a response within 72 hours. We will work with you to understand and address the issue before any public disclosure.

Supported Versions

Version Supported
latest Yes

Security Practices

  • Scheduled-job error summaries redact common credential formats before storage or display.
  • Local configuration files with credentials (config.ini) are ignored by the repository.
  • The Docker entrypoint applies the configured PUID/PGID before starting Comicarr.
  • Database helpers support parameterized statements; contributors should preserve that pattern in new queries.
  • The support bundle contract limits exported fields to its allowlist and marks each bundle for operator review before sharing.

Known Scanner Findings

The following items may be flagged by automated security scanners but are not security vulnerabilities:

ComicVine API Key in comicarr/_vendor/comictaggerlib/comicvinetalker.py

This is the ComicTagger project's publicly distributed default API key, inherited from the upstream Mylar3 codebase. It is not a private credential — the same key is visible in the public ComicTagger repository.

CherryPy Test Certificate in Git History

A test RSA certificate (cherrypy/test/test.pem) exists in historical commits from when CherryPy was vendored. This is a well-known test fixture from the CherryPy project, not a production credential. The file was removed when vendored dependencies were cleaned up.

Dependencies

We monitor dependencies for known vulnerabilities via GitHub Dependabot. If you notice a dependency with a known CVE, please open an issue or PR with the update.

There aren't any published security advisories