This repository is intended to be used with your own API credentials and local OAuth files.
Please do not report security vulnerabilities in public issues.
Instead, contact the maintainer privately and include:
- A description of the issue
- Reproduction steps
- Potential impact
- Any suggested mitigation
Never commit any of the following:
.envclient_secret.jsontoken.pickle- Raw API keys, OAuth tokens, or private credentials
If a secret is committed accidentally:
- Revoke and rotate it immediately.
- Remove it from git history.
- Update any affected deployment secrets.