Please do not open a public issue for security problems. Use GitHub's private reporting instead: https://github.com/hdrees/clockodo-cli/security/advisories/new
Include what you found, how to reproduce it and the affected version (./clockodo version). You can expect a first reply within a few days.
--curlandDEBUG=1output contain your Clockodo API key (DEBUGmasks it to 4 characters,--curldoes not). Do not paste either into issues, chats or logs.- If a key was exposed, rotate it in your Clockodo account.
.envmust never be committed.