windyboy a3ee8c09cf security: scrub live credentials from tracked notes; point values at Vaultwarden
- replace real keys/passwords/tokens/connection strings with {{SECRET_*}}
  placeholders across 24 files (review-named 12 + noise-audit finds:
  WAQI/Dovecot/GPS/VPN subscriptions/Work runbooks/Plane API key)
- widen verifier: OPENSSH/RSA key headers, hyphenated sk-/prefixed sk-,
  credential assignments & table cells, telegram bot tokens, conn strings
- placeholder/default-value/config-name exemptions to kill doc FPs
- skip .obsidian plugin code and frozen Inbox-Clippings from value scan
- GIT_WORKFLOW: no git add ., verifier before commit, force-push exception
- final regression: 0 flagged in tracked scope (was 43)
2026-09-26 12:26:57 +08:00
2026-04-15 14:34:24 +08:00

My Obsidian Vault

Personal knowledge base using the PARA method, version-controlled with Git.

Structure

00_Inbox/           Capture → process weekly
01_Projects/        Time-bound work
02_Areas/           Ongoing responsibilities
03_Resources/       Reference materials
04_Archive/         Completed items & clippings
05_Attachments/     Media files
06_Metadata/        Templates & reference docs

Entry Points

  • AGENTS.md — operations manual for AI agents (permission table, safety rules, code style)
  • 06_Metadata/Reference/PARA_METHOD.md — PARA methodology reference
  • 06_Metadata/Reference/GIT_WORKFLOW.md — git workflow guide

Scripts

pnpm lint              # Lint + format (auto-fix)
pnpm lint:check        # Check only
pnpm format            # Prettier format
pnpm vault:stats       # Vault statistics

CI

GitHub Actions runs lint, format check, and secret scanning on every push/PR to main.

S
Description
No description provided
Readme
67 MiB
Languages
JavaScript 61.2%
PowerShell 17.9%
Python 12.6%
Shell 8.3%