critical
suspicious.env_credential_access
- Location
- src/lib/gift-proof-helpers.js:45
- Finding
- Environment variable access combined with network send.
- Evidence
export function resolveBasememeApiToken(options = {}, env = process.env) {
AdvisoryAudited by Static analysis on May 10, 2026.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal
export function resolveBasememeApiToken(options = {}, env = process.env) {const bearer = [REDACTED](options);