BlueGreenPilot is designed to guide deployment safety, not to hold credentials.
Do not commit secrets, tokens, private keys, database URLs with credentials, or
cloud provider credentials into .bluegreenpilot/config.yaml, state files, or
history files.
Report security issues privately to the repository maintainers once the project is published.