critical
suspicious.env_credential_access
- Location
- dist/provider-BZtjA1y_.js:2159
- Finding
- Environment variable access combined with network send.
- Evidence
function resolvePreferencesStorePath(env = process.env) {
AdvisoryAudited by Static analysis on May 20, 2026.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal
function resolvePreferencesStorePath(env = process.env) {if (params.config.token?.trim()) headers.Authorization = [REDACTED]();