Use GitHub's private reporting: Report a vulnerability. It's enabled on this repo, so the report stays private until there's a fix.
Please don't open a public issue for anything exploitable.
Useful things to include: the version or image tag you're on, what an attacker can do with it, and a reproduction if you have one. A rough description beats no report.
I'll acknowledge within a few days and keep you posted in the advisory thread. Once it's fixed I'll credit you in the advisory unless you'd rather I didn't.
If the issue is in upstream Agregarr rather than this fork, report it here anyway and I'll take it to them.
develop only, which is what the bitr8/agregarr:develop image tracks. Fixes land there; older tags don't get backports.