[Bug] False positive security flag on legitimate credential rotation workflow

Status Open
Reported on v2.1.232
Maintainer reply None cached
Activity 0 comments · opened Aug 15, 2026

Bug Description
False positive on legitimate defensive-security work. Session was an authorized credential-rotation task on my own Supabase project: migrating an exposed ▎ service_role key to Supabase's new revocable key format, following official Supabase migration docs. The flagged message was planning a safe rotation sequence — ▎ inventory consumers, watch API logs until the legacy key goes idle, then revoke — explicitly to avoid breaking production. No exploitation, no third-party target, ▎ no evasion. Standard incident-response hygiene on owned infrastructure.

Environment Info

  • Platform: win32
  • Terminal: windows-terminal
  • Version: 2.1.232
  • Feedback ID: a9b12f7d-0fcb-4caf-aa2e-c45776d8993a

Errors

[]

View original on GitHub ↗