a3ee8c09cff52d1b953a17424f2b496901f3f651
- replace real keys/passwords/tokens/connection strings with {{SECRET_*}}
placeholders across 24 files (review-named 12 + noise-audit finds:
WAQI/Dovecot/GPS/VPN subscriptions/Work runbooks/Plane API key)
- widen verifier: OPENSSH/RSA key headers, hyphenated sk-/prefixed sk-,
credential assignments & table cells, telegram bot tokens, conn strings
- placeholder/default-value/config-name exemptions to kill doc FPs
- skip .obsidian plugin code and frozen Inbox-Clippings from value scan
- GIT_WORKFLOW: no git add ., verifier before commit, force-push exception
- final regression: 0 flagged in tracked scope (was 43)
My Obsidian Vault
Personal knowledge base using the PARA method, version-controlled with Git.
Structure
00_Inbox/ Capture → process weekly
01_Projects/ Time-bound work
02_Areas/ Ongoing responsibilities
03_Resources/ Reference materials
04_Archive/ Completed items & clippings
05_Attachments/ Media files
06_Metadata/ Templates & reference docs
Entry Points
AGENTS.md— operations manual for AI agents (permission table, safety rules, code style)06_Metadata/Reference/PARA_METHOD.md— PARA methodology reference06_Metadata/Reference/GIT_WORKFLOW.md— git workflow guide
Scripts
pnpm lint # Lint + format (auto-fix)
pnpm lint:check # Check only
pnpm format # Prettier format
pnpm vault:stats # Vault statistics
CI
GitHub Actions runs lint, format check, and secret scanning on every push/PR to main.
Languages
JavaScript
61.2%
PowerShell
17.9%
Python
12.6%
Shell
8.3%