Phase-3 review finding (HIGH/security). DiagnosticsCollector.kt:70 captures throwable?.stackTraceToString() verbatim into DebugReport.toSubmissionPayload()/toStorageJson() with NO PII scrubbing. Jakarta/Angus Mail + java.net exceptions embed server hostnames (ConnectException: Failed to connect to imap.example.com/1.2.3.4:993) and auth failures can echo the username/email. Violates the hard PII-free-reports constraint; crash reports auto-surface at startup (#255). Fix: scrub the stack trace (strip host:port tokens + email-matching substrings; or keep only class+frames, drop messages) before it enters the report. Add a unit test asserting hosts/emails are removed. (The logs/accounts/settings fields are already clean — this is the one unscrubbed free-text field.)
Phase-3 review finding (HIGH/security). `DiagnosticsCollector.kt:70` captures `throwable?.stackTraceToString()` verbatim into `DebugReport.toSubmissionPayload()`/`toStorageJson()` with NO PII scrubbing. Jakarta/Angus Mail + java.net exceptions embed **server hostnames** (`ConnectException: Failed to connect to imap.example.com/1.2.3.4:993`) and auth failures can echo the **username/email**. Violates the hard PII-free-reports constraint; crash reports auto-surface at startup (#255). **Fix:** scrub the stack trace (strip host:port tokens + email-matching substrings; or keep only class+frames, drop messages) before it enters the report. Add a unit test asserting hosts/emails are removed. (The logs/accounts/settings fields are already clean — this is the one unscrubbed free-text field.)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-3 review finding (HIGH/security).
DiagnosticsCollector.kt:70capturesthrowable?.stackTraceToString()verbatim intoDebugReport.toSubmissionPayload()/toStorageJson()with NO PII scrubbing. Jakarta/Angus Mail + java.net exceptions embed server hostnames (ConnectException: Failed to connect to imap.example.com/1.2.3.4:993) and auth failures can echo the username/email. Violates the hard PII-free-reports constraint; crash reports auto-surface at startup (#255). Fix: scrub the stack trace (strip host:port tokens + email-matching substrings; or keep only class+frames, drop messages) before it enters the report. Add a unit test asserting hosts/emails are removed. (The logs/accounts/settings fields are already clean — this is the one unscrubbed free-text field.)