fix(security): unify public-only token filtering in API queries and repo access #144
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Public-only tokens can access private repos/orgs through gaps in API query filtering.
Upstream Reference
Severity: High
Private repository data accessible via public-only scoped tokens.
Action
Cherry-pick from upstream
release/v1.26.Authored-by: Claude Opus 4.6 (1M context) noreply@anthropic.com