pub fn scan_path_refs(path: &Path) -> CliResult<BTreeSet<SecretRef>>
Parse path (tolerating secret directives) and return its unique secret refs.
path