TaintedSystemSecret

This is a security issue, reported by security analysis: it flags a potential vulnerability rather than a type error or a code-quality problem.

Emitted when data marked as a system secret is detected somewhere it shouldn’t be.

<?php

/**
 * @psalm-taint-source system_secret
 */
function getConfigValue(string $data) {
    return "$omePa$$word";
}

echo getConfigValue("secret");