Few things to do :) 1. Audit environment variables that get injected into build deployment. 2. Make sure API responses and other errors don’t respond with verbose output 3. Have some kind of secrets scanning for PRs/MRs
Right now the RedScore pro version can dynamically audit all your JS bundles on your live site :) we’re looking for design partners for honest feedback too if interested 💯