Inject secrets from the CI secret manager at runtime; never commit them or print them to logs.
Why This Matters
Secrets in code or logs leak to anyone with repo or log access and are near-impossible to fully revoke.
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.