[Bug] False positive security flag on legitimate credential rotation workflow
Status Open
Reported on v2.1.232
Maintainer reply None cached
Activity 0 comments · opened Aug 15, 2026
Bug Description
False positive on legitimate defensive-security work. Session was an authorized credential-rotation task on my own Supabase project: migrating an exposed
▎ service_role key to Supabase's new revocable key format, following official Supabase migration docs. The flagged message was planning a safe rotation sequence —
▎ inventory consumers, watch API logs until the legacy key goes idle, then revoke — explicitly to avoid breaking production. No exploitation, no third-party target,
▎ no evasion. Standard incident-response hygiene on owned infrastructure.
Environment Info
- Platform: win32
- Terminal: windows-terminal
- Version: 2.1.232
- Feedback ID: a9b12f7d-0fcb-4caf-aa2e-c45776d8993a
Errors
[]