Also be interesting to see what trufflehog finds (should be false positive)
https://github.com/trufflesecurity/trufflehog
Where are you storing the creds to get the secret from the vault?
This is the secret zero problem and other platforms solve it in other ways such as HSM