| Version | Supported |
|---|---|
Latest (main) |
✅ |
| Previous minor | |
| Older | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
To report a security issue, open a GitHub Security Advisory (private disclosure). You can also use the "Report a vulnerability" button on the Security tab.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Affected versions
- Any suggested fix, if you have one
- Acknowledgement within 48 hours
- Assessment and triage within 5 business days
- Fix and advisory published after a patch is ready (coordinated disclosure)
This policy covers the awesome-python-auth PyPI package. It does not cover third-party dependencies — please report those directly to their respective maintainers.
- Never commit
access_token_secret,refresh_token_secret, or other secrets to source control. - Rotate JWT secrets if you suspect they have been exposed.
- Keep the library updated to receive security patches (
pip install --upgrade awesome-python-auth). - Set
cookie_secure=Trueand use HTTPS in production.