Bahn: aisupport, Analyse-O2C-C2S, awesome-bahn-mcp-servers, beam-mcp,
Confluence_Bot, db-planet-mcp-server, O2C-Harness, project-audit,
Projekt-KIQ-HP, teamlandkarte-mcp
Dhive: Jury-Voting
Privat: CV, NoteGraph (NOTE: NoteGraph needs complete redo after consolidation)
Shared: AI-Orchestrator, OrgMyLife, power_skills_and_more
Shared/references: symphony (read-only)
Bahn repos remain available as independent remotes - this monorepo
pulls them in via subtree, the originals are untouched.
20 lines
686 B
Markdown
20 lines
686 B
Markdown
# Security notes
|
|
|
|
## Credentials
|
|
|
|
- `config.toml` is intentionally ignored via `.gitignore`.
|
|
- If `config.toml` (or any file containing credentials) was ever committed to git history, treat those credentials as compromised.
|
|
|
|
## Credential rotation checklist
|
|
|
|
1. Rotate the database password / token.
|
|
2. Invalidate any exposed API tokens.
|
|
3. Re-issue credentials with least-privilege read-only access.
|
|
4. Audit logs for suspicious access.
|
|
|
|
## Git history cleanup (if needed)
|
|
|
|
If a secret accidentally entered git history, remove it from history using secure tools (for example `git filter-repo`) and force-push.
|
|
|
|
Do **not** rely on a simple revert; secrets remain accessible in history.
|