Please report security vulnerabilities privately — not in a public issue or pull request.
Open a private advisory directly: https://github.com/Bynn-Intelligence/zoreal-oauth2-python/security/advisories/new
or open the repository's Security tab and choose Report a vulnerability. The report is visible only to the maintainers.
We aim to acknowledge a report within 3 business days and to keep you updated as we investigate. Please allow a reasonable window to ship a fix before any public disclosure.
This repository is one client library in the Login with ZOREAL family. If the issue is in the ZOREAL service itself rather than this library, start a private report here anyway and we will route it to the right team.
Security fixes are released against the latest published version. Pin to a released version and upgrade promptly when an advisory is published.