This library handles YNAB Personal Access Tokens — credentials to real financial data. Treat every report accordingly.
Only the latest v1.x release receives security fixes.
Do not open a public issue. Use GitHub's private vulnerability reporting: Report a vulnerability.
Reports are acknowledged within 7 days. Disclosure is coordinated: we agree on a timeline together before anything becomes public.
Anything that could expose a token (logs, errors, User-Agent, headers to unexpected hosts), weaken TLS posture, or make the client emit requests the caller did not ask for. The token-redaction promise is asserted by the integration suite on real traffic — a redaction bypass is a vulnerability, not a bug.