Do not report private credentials or sensitive details in public issues. Contact the repository owner privately through GitHub for security concerns.
The default branch is scanned on every push and pull request and on a weekly
schedule. GitHub secret scanning and push protection are enabled at repository
level. Keep runtime credentials in the deployment platform's secret store;
never commit local .env, service-account JSON, private keys, or access tokens.