Security fixes are applied on the latest release on the default branch.
Please open a GitHub Security Advisory or contact the repository owner privately. Do not open public issues for undisclosed vulnerabilities.
- Never commit Spotify
client_id,client_secret, or OAuth tokens. - Configure credentials via environment variables (
SPOTIPY_CLIENT_ID,SPOTIPY_CLIENT_SECRET,SPOTIPY_REDIRECT_URI). - If credentials were ever committed to git history, rotate them in the Spotify Developer Dashboard immediately.