Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)Creditssanil18Referenceshttps://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48https://github.com/go-gitea/gitea/releases/tag/v1.27.0https://blog.gitea.com/gitea-1.27.0-is-released/