Block a user
API allows unbounded queries causing Gunicorn worker timeouts
Rotate credentials committed in .env
Follow-up: Dev PostgreSQL password for sba_admin was also rotated on 2026-04-01. The old placeholder value your_production_password has been replaced with a secure generated password. Dev API…
Rotate credentials committed in .env
Rotate secrets exposed in git history
Resolved via PR #52
- Real API token (
Tp3aO3jhYve5NJF1IqOmJTmk) scrubbed fromdocs/PD_CARDS_CLI_REFERENCE.md— replaced withyour-api-token-hereplaceholder - Full audit of tracked…
Rotate credentials committed in .env
Credential Rotation — Closed
All remediation tasks for this issue are complete as of 2026-04-01.
Rotation Actions
- API_TOKEN — rotated on prod (
ssh akamai) and dev (`ssh…
cal
deleted branch fix/docker-compose-secrets-untrack from cal/paper-dynasty-discord
2026-04-01 18:02:38 +00:00
fix: remove docker-compose.yml from tracking, add example template
cal
pushed to fix/docker-compose-secrets-untrack at cal/paper-dynasty-discord
2026-04-01 18:02:32 +00:00
chore: add .env.example with placeholder values
cal
deleted branch fix/scrub-exposed-credentials from cal/paper-dynasty-card-creation
2026-04-01 18:02:04 +00:00
fix: scrub exposed credentials from docs
Rotate secrets exposed in git history
cal
pushed to fix/scrub-exposed-credentials at cal/paper-dynasty-card-creation
2026-04-01 18:01:59 +00:00
fix: remove docker-compose.yml from tracking, add example template
Security Review — APPROVED (no real secrets found)