From ccf056de27e2385775a5a13f6786610e50ae9cd4 Mon Sep 17 00:00:00 2001 From: Sam P Date: Sun, 13 Sep 2026 10:40:54 +0530 Subject: [PATCH] Potential fix for code scanning alert no. 4: Clear-text logging of sensitive information Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- blossom/src/index.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/blossom/src/index.ts b/blossom/src/index.ts index a66d2ab..f7ebf66 100644 --- a/blossom/src/index.ts +++ b/blossom/src/index.ts @@ -245,8 +245,8 @@ if (config.dashboard.enabled) { app.use(mount("/api", adminApi.routes())).use(mount("/api", adminApi.allowedMethods())); app.use(mount("/admin", serve(path.resolve(__dirname, "../admin/dist")))); - // never log the password itself - logger(`Dashboard started with username=${config.dashboard.username} (password length: ${password.length})`); + // never log sensitive auth details + logger("Dashboard started"); } try {