Do not commit:
- OAuth tokens, cookies, passwords, one-time codes, device credentials, or API keys
- Private playlist exports or account-library manifests
- Phone numbers or other login identifiers
- Migration checkpoints containing user-specific catalog data
If sensitive data is committed, revoke the credential first, then remove it from Git history before publishing another revision.
Open a GitHub issue for workflow or code vulnerabilities that do not contain sensitive data. Do not paste credentials or private music-library data into an issue.