Security fixes are provided for the latest published beta. Older portable builds should be replaced rather than retained.
Use GitHub private vulnerability reporting. Do not open a public issue for credential exposure, arbitrary file access, command execution, unsafe update/download behavior, or network-service flaws.
Include the affected version, reproduction steps, impact, and a minimal proof-of-concept. Do not include Apple TV pairing credentials, copyrighted media, third-party access tokens, or unrelated personal data.
The maintainer will acknowledge a useful report as soon as practical, keep discussion private while a fix is prepared, and credit the reporter if desired.
Every release publishes SHA-256 checksums. Public binaries are built from a tagged revision. Until trusted code signing is available, releases are clearly identified as unsigned. The optional FFmpeg download is accepted only when the archive and extracted executable hashes match pinned values.
The canonical optional-support addresses are committed in
src/violetrelay/support.py and repeated in the tagged README. Treat an
unexpected donation-address change as a security-sensitive supply-chain event
and report it privately.