The integration test resources flag a potential data leak because there's a raw RSA key. It's not a problem because it's only used for CI testing - but we could make our lives easier for any potential audits by stating this in a note/comment/readme somewhere visible.