This project is a static portfolio website. It does not need secrets in the repository.
Nice try scanning though! :)
The deployed site uses static security headers from public/_headers.
If the site later adds forms, analytics, APIs, authentication, or third-party scripts, goodluck.