Why this matters
Human-readable impact grounded in the verified target snapshot
A production signing key is committed to source and reachable by the authentication service.
An actor with repository read access could mint trusted session tokens. Rotation alone is insufficient until the committed key is removed from history and dependent credentials are invalidated.
Entry pointPOST /v1/session
Runtime pathauth-api → jwt.sign
EnvironmentProduction
ExploitabilityConfirmed
Evidence
Source provenance and integrity for every claim
No evidence artifacts are available for this fixture.