Security fixes are applied to the latest release in the current major/minor line maintained on github.com/mostafa/django-saml2-auth. Use the latest published version on PyPI when possible.
Please do not open a public GitHub issue for unfixed security problems.
Instead, report details privately so we can coordinate a fix and disclosure:
- Use GitHub private vulnerability reporting for this repository, if enabled, or
- Email the maintainer with a clear subject line (e.g. “Security: django-saml2-auth”) and include steps to reproduce, impact, and affected versions if known.
We aim to acknowledge receipt within a few business days and to work toward a patched release and advisory timeline that balances user safety with responsible disclosure.
Security fixes are summarized in GitHub Releases and, when appropriate, as a GitHub Security Advisory.