Please do not open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting: Report a vulnerability
I'll respond within 48 hours and work with you on a fix before public disclosure.
- Auth token handling / Keychain storage
- API request security (HTTPS enforcement, header exposure)
- Any data leakage between Gitea accounts