What to build
Confirm whether the Stack Auth keys and Neon database owner credentials that were previously committed (documented in SECURITY_NOTICE.md) were actually rotated. If not, rotate them now in the Stack Auth and Neon dashboards and update Vercel environment variables. Record the rotation date in SECURITY_NOTICE.md. Optionally scrub the secrets from git history afterwards.
Context: the secrets are still retrievable from git history today. See AUDIT_REPORT.md §3.3 (branch claude/repo-audit-improvement-ozhlau), task 0.4.
Human required: needs access to the Stack Auth dashboard, Neon console, and Vercel project settings.
Acceptance criteria
Blocked by
None - can start immediately
What to build
Confirm whether the Stack Auth keys and Neon database owner credentials that were previously committed (documented in SECURITY_NOTICE.md) were actually rotated. If not, rotate them now in the Stack Auth and Neon dashboards and update Vercel environment variables. Record the rotation date in SECURITY_NOTICE.md. Optionally scrub the secrets from git history afterwards.
Context: the secrets are still retrievable from git history today. See AUDIT_REPORT.md §3.3 (branch
claude/repo-audit-improvement-ozhlau), task 0.4.Human required: needs access to the Stack Auth dashboard, Neon console, and Vercel project settings.
Acceptance criteria
DATABASE_URLrecoverable from git history no longer authenticatesBlocked by
None - can start immediately