You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Patches:
Hardened the app updater so GitHub release downloads must come from trusted HTTPS GitHub hosts, and asset filenames are sanitized before saving.
Replaced unsafe zip extraction in the updater with a guarded extraction path that blocks path traversal outside the temporary update folder.
Tightened the Cloudflare API client so bearer-token requests are only configured over HTTPS, removing the unnecessary plain-HTTP adapter mount.
Cleaned up token_store.py by renaming one-character variables to descriptive names and adding a best-effort restrictive file-permissions step after saving encrypted tokens.
Backout process: rollback to last version
Risk: low