release / go (push) Successful in 1m47s
release / govulncheck (push) Successful in 18s
release / web (push) Successful in 1m15s
release / integration (push) Successful in 4m44s
release / android (push) Successful in 5m37s
release / Build signed APK (releases and dev) (push) Successful in 5m43s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m13s
release / Verify release artifacts (tag releases only) (push) Skipped
Cleartext stays permitted app-wide for LAN servers and UPnP (#2439), but a password or session cookie sent over plain HTTP to a public address can be read by anyone on the path. A network interceptor now refuses a cleartext request to the Minstrel server when the connection lands on a public address, before any request byte is written. Checked per connection, on the address actually reached, rather than when the URL is typed: a name that resolved to the home network at entry resolves to a public address once the phone leaves home. Allowed: loopback, 10/8, 172.16/12, 192.168/16, link-local, 100.64/10 (Tailscale and other overlay VPNs) and fc00::/7. Only requests BaseUrlInterceptor tagged as server-bound are checked; external fetches and UPnP are untouched. The refusal has its own message. Family baseline #5105, practice 13. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>