Secret Hygiene
A practical workflow for credential management: detecting leaks, rotating cleanly, and preventing recurrence.
When to invoke
- A secret was committed to git, or a private repo went public
- A contributor leaves the project, or access scope changes
- A credential turned up in a public dump, paste, or leak feed
- Periodic audit (quarterly is reasonable)
- Onboarding a repo, hosting account, or VPS you inherited
Step 1 — Inventory what you have
You cannot rotate secrets
[Description truncada. Veja o README completo no GitHub.]