Skip to content

Verify/rotate credentials exposed in git history and record the outcome #22

Description

@paccloud

What to build

Confirm whether the Stack Auth keys and Neon database owner credentials that were previously committed (documented in SECURITY_NOTICE.md) were actually rotated. If not, rotate them now in the Stack Auth and Neon dashboards and update Vercel environment variables. Record the rotation date in SECURITY_NOTICE.md. Optionally scrub the secrets from git history afterwards.

Context: the secrets are still retrievable from git history today. See AUDIT_REPORT.md §3.3 (branch claude/repo-audit-improvement-ozhlau), task 0.4.

Human required: needs access to the Stack Auth dashboard, Neon console, and Vercel project settings.

Acceptance criteria

  • The old DATABASE_URL recoverable from git history no longer authenticates
  • The old Stack Auth secret server key is revoked
  • Production still works after rotation (login, OAuth, sync)
  • SECURITY_NOTICE.md records the rotation date

Blocked by

None - can start immediately

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingready-for-humanRequires human implementation

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions