Report potential vulnerabilities privately with affected path and impact.
- Never commit tokens, private keys, or local key file paths.
- Keep
.envlocal and untracked. - Use placeholder values in examples.
- Revoke exposed credentials.
- Rotate and redeploy.
- Remove from current branch.
- Rewrite history if committed.
- Re-run secret scans.