Problem
.env is tracked by Git and pyproject.toml force-includes it in wheel/sdist artifacts. The file contains a non-placeholder PurelyMail API key and must be treated as exposed.
Required scope
- Revoke and rotate the current PurelyMail credential.
- Remove
.env from Git history and package inclusion; add a safe .env.example.
- Load credentials only from CI/runtime secrets.
- Add secret scanning and a release check that wheel/sdist artifacts contain no credentials.
- Update Harbor/native documentation so credentials are injected, never packaged.
Acceptance criteria
git ls-files .env is empty.
- Built wheel and sdist contain no
.env or credential values.
- CI fails on newly introduced secrets.
- Historical release artifacts are audited and the rotation is documented.
This is tracked as SEC-001 in docs/codebase-evaluation-2026-09.md. @Perry2004 please review ownership and the rotation plan.
Problem
.envis tracked by Git andpyproject.tomlforce-includes it in wheel/sdist artifacts. The file contains a non-placeholder PurelyMail API key and must be treated as exposed.Required scope
.envfrom Git history and package inclusion; add a safe.env.example.Acceptance criteria
git ls-files .envis empty..envor credential values.This is tracked as
SEC-001indocs/codebase-evaluation-2026-09.md. @Perry2004 please review ownership and the rotation plan.