miniblue is a local development tool. It is not designed for production use and should never be exposed to the internet.
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email: devopsbymo@gmail.com
- Include a description of the vulnerability and steps to reproduce
We will respond within 48 hours and work with you to understand and address the issue.
Since miniblue is a local emulator, security concerns are primarily around:
- Preventing unintended network exposure
- Ensuring mock tokens cannot be confused with real Azure tokens
- Safe handling of user-provided data in the in-memory store