Secret env files committed due missing ignore rule
Bad input: .env.production accidentally tracked in repo history.
Failure: Credential leakage risk and emergency rotation overhead.
Fix: Add secret-file patterns early and use pre-commit secret scanning.