Security Runbook
Check:
If a credential is exposed
- Revoke/rotate it immediately.
- Remove it from active configuration.
- Search repository history and deployment logs.
- Determine exposure scope.
- Review affected authentication/integration activity.
- Replace the secret with a newly generated value.
- Document the incident.
If unauthorized issue access is reported
text
user identity
project membership
role/permission
issue visibility
API authorization
audit historyDo not rely solely on frontend state when investigating access control.
Something wrong or missing on this page?Report a docs issue