When using vsce package command, errors are returned for manifest.spdx.json files claiming they are Send Grid secrets, however they are just hashes as per SPDX SBOM spec.
Example file with false positive: https://www.powershellgallery.com/packages/PSRule.Rules.Azure/1.41.0/Content/_manifest%5Cspdx_2.2%5Cmanifest.spdx.json