Issue per-service credentials from a secrets manager, rotate them on a schedule, and keep them out of source control.
Why This Matters
Shared, never-rotated credentials linger in code and chat, so a single leak grants long-lived database access.
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.