Security for the Pryv open-source projects, including this repository, is handled through a single coordinated vulnerability disclosure policy.
Please do not open a public issue for security vulnerabilities. Report them privately instead:
- Read the full policy (scope, timelines, safe harbor): https://github.com/pryv/open-pryv.io/blob/master/SECURITY.md
- Open a private advisory on this repository: https://github.com/pryv/app-web-auth3/security/advisories/new
- Or email security-dev@pryv.com.