Credential-looking files that are committed to git are reported separately and explained.
What's wrong with this entry?
Files whose names look like credentials but which are tracked in git are now reported separately from untracked ones, and the skip message explains that file sync never carries them while a committed version still reaches the next session through git.
- Adds a
sensitive_trackedskip reason and its own pass in the upload pipeline.
(file sync never carries those; a committed version reaches the next session through git)
Strings lifted out of the shipped bundle, so the claim above can be checked against them.