# Security findings (sanitized)

Scanner: static review + dependency advisory · sample package

| Sev | Finding | Status |
|---|---|---|
| info | Public `/health` unauthenticated (by design) | accepted |
| low | Default demo token documented in README only | accepted for sample |
| medium | Lane C hard-coded fixture password | **blocked lane C** — not in winner |
| high | none | — |
| critical | none | — |

**Winner (Lane B):** no high/critical; max severity informational/low.  
**Security gate:** PASS for promoted artifact.
