Security fixes are applied to the current Docker image and latest tagged release.
Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue containing credentials, cookies, private URLs, tokens, or an unpatched exploit.
Include the affected version or image digest, deployment type, reproduction steps, and expected impact. Reports concerning upstream yt-dlp behavior should also identify the installed yt-dlp --version output.