The secrets job appears to be falling back to a full repository scan,
which surfaces many existing false positives outside this PR.
Could maintainers confirm whether the baseline/diff scan is configured correctly?
Originally posted by @yuuuuuuan in #38496 (comment)