Why
Tracked application settings contain live-looking payment credentials in a public repository. Assume every committed value has been compromised. Do not paste credential values into this issue or comments.
Scope
- Inventory secrets in current files, tags, releases, package artifacts, and git history.
- Revoke and rotate affected provider credentials immediately.
- Replace committed values with placeholders and load local secrets from user-secrets or environment variables.
- Purge leaked values from history where practical and invalidate old package/release artifacts if they contain them.
- Add automated secret scanning and a documented response procedure.
Acceptance criteria
Why
Tracked application settings contain live-looking payment credentials in a public repository. Assume every committed value has been compromised. Do not paste credential values into this issue or comments.
Scope
Acceptance criteria