Mailing lists:

General

Security

To be credited for the discovery of a vulnerability, you must provide a real first name and last name (not a GitHub handle) and/or a real company (not GitHub, unless you are employed by GitHub).
The number of security advisories has increased recently, which may sound alarming. AI-powered tools have fundamentally changed the security landscape, making it much easier and faster to identify potential vulnerabilities and weaknesses.

While this may initially seem like a bad thing, it is actually a positive development: it is far better to remain vigilant and fix security issues than to overlook them and have a false sense of security.

Security advisories are not necessarily a sign of poor code quality. They also reflect a project's visibility, widespread use, and active security scrutiny. Open-source software can be publicly inspected, tested, and continuously improved—provided that reported issues are addressed promptly.

The practical takeaway is clear: use the latest mature version of pac4j and apply security updates as soon as possible.