Skip to content

Security: auth0/auth0-kmp

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

If you believe you have found a security vulnerability in this SDK, report it through Auth0's Responsible Disclosure Program. That page details the disclosure procedure, what is in scope, and what to expect after you submit a report.

Please include as much of the following as you can, so we can reproduce and assess the issue quickly:

  • The affected module(s) and SDK version.
  • Which platform(s) are affected (Android, iOS, or both).
  • Steps to reproduce, ideally against one of the sample apps.
  • The impact you believe the issue has.

Supported Versions

Security fixes are released against the latest published version of the SDK. We recommend always depending on the most recent release; see the CHANGELOG for what is current.

Pre-release versions (-beta, -rc) are not covered by long-term support — fixes land in the next pre-release or in the next stable version rather than being backported.

There aren't any published security advisories