Mailing lists:
General
-
If you need help and have any question/issue when using pac4j, please use Stack Overflow with the pac4j tag.
Old messages can be read on the pac4j-users Google group -
If you want to contribute or discuss some development/design issue, please use the pac4j-dev Google group
-
To receive the release announcements, please subscribe to the pac4j-announce Google group.
Security
-
To receive the security alerts, please subscribe to the pac4j-security Google group
-
To privately report any security issue, send an email to [email protected]. Read the security policy first: it explains what to include in your report, which versions are supported and how the disclosure works.
To be credited for the discovery of a vulnerability, you must provide a real first name and last name (not a GitHub handle) and/or a real company (not GitHub, unless you are employed by GitHub).
The number of security advisories has increased recently, which may sound alarming. AI-powered tools have fundamentally changed the security landscape, making it much easier and faster to identify potential vulnerabilities and weaknesses.
While this may initially seem like a bad thing, it is actually a positive development: it is far better to remain vigilant and fix security issues than to overlook them and have a false sense of security.
Security advisories are not necessarily a sign of poor code quality. They also reflect a project's visibility, widespread use, and active security scrutiny. Open-source software can be publicly inspected, tested, and continuously improved—provided that reported issues are addressed promptly.
The practical takeaway is clear: use the latest mature version of pac4j and apply security updates as soon as possible.
While this may initially seem like a bad thing, it is actually a positive development: it is far better to remain vigilant and fix security issues than to overlook them and have a false sense of security.
Security advisories are not necessarily a sign of poor code quality. They also reflect a project's visibility, widespread use, and active security scrutiny. Open-source software can be publicly inspected, tested, and continuously improved—provided that reported issues are addressed promptly.
The practical takeaway is clear: use the latest mature version of pac4j and apply security updates as soon as possible.