Karate DSL report serialization exposes karate-config.js secrets despite showConfig flag
Configuration leakage in HTML reports Karate merges karate-config.js and environment-specific variants at startup, then serializes the full configuration object into the default HTML and JUnit reports. The 1.x release introduced an undocumented karate.configure('report', { showConfig: false }) option intended to suppress this output, but the flag does not co