critical
suspicious.exposed_secret_literal
- Location
- dist/discovery.js:210
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
const bearerToken = [REDACTED] ?? await generateBearerTokenFromIam({
AdvisoryAudited by Static analysis on May 20, 2026.
Detected: suspicious.exposed_secret_literal
const bearerToken = [REDACTED] ?? await generateBearerTokenFromIam({