How do you handle source maps in production builds?
Saw a case today where a `.map` file in a published npm package ended up exposing the original source because it included embedded sources (`sourcesContent`).
It didn’t look like a breach, just a build artifact making it into production, which makes it more interesting from a JS tooling perspective.
In most setups, this comes down to how bundlers are configured and whether final build outputs are actually inspected before publishing. Since npm packages ship whatever ends up in the output (unless explicitly excluded), it’s easy for something like this to slip through.