API keys, passwords or tokens committed into the repo.
Seriouscurl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
README.md:21
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
Seriouscurl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
README.md:25
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
Seriouscurl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
setup-free-stack.sh:25
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.