Skip to content

chore: stop naming client projects in a public repository - #114

Merged
projectdelta6 merged 2 commits into
mainfrom
chore/scrub-internal-references
Aug 27, 2026
Merged

projectdelta6 merged 2 commits into
mainfrom
chore/scrub-internal-references

Conversation

@projectdelta6

Copy link
Copy Markdown
Collaborator

Follow-up to removing a client name from the 1.9.0 release notes — the same thing was in the tree.

publishing-check/build.gradle.kts named two client apps and disclosed which toolbox modules each depends on. That is more than the comment needed to make its point. The reasoning — why a green consumer proved nothing about the 1.8.2 regression — is fully preserved; only the identities are gone.

Nav3Navigation/README.md credited a named client team. Thanks kept, name dropped.

Two matches in the sweep were false positives and are untouched: "accelerate" as a verb in the root README, and progressReporter matching "Porter".

🤖 Generated with Claude Code

projectdelta6 and others added 2 commits August 26, 2026 16:24
Two places named internal client projects. The publishing-check comment was the
worse of them: it named two of them and disclosed which toolbox modules each app
depends on, which is more than the comment needed to make its point. Generalised to
"one consumer" and "another" — the reasoning about why a green consumer proved
nothing is what mattered, not which apps they were.

The Nav3Navigation credit keeps the thanks and drops the project name.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The AuthApi KDoc published a working email and password pair — a real corporate
address alongside `secret123` — for a live Forge-hosted backend. The host now
returns 522 (Cloudflare up, origin gone), so it appears decommissioned, but the
pairing should not have been committed regardless: an email and password published
together are what credential-stuffing lists are built from, and that risk attaches
to the address rather than to the server.

Scrubbing the file does not undo it — git history keeps both values — so treat them
as harvested and rotate the password anywhere it was reused.

Also notes at BASE_URL that the host is gone, so the next person to try the
network-backed parts of the demo learns it from the source rather than from a
timeout.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@projectdelta6 projectdelta6 reopened this Aug 27, 2026
@projectdelta6
projectdelta6 merged commit 1ac4311 into main Aug 27, 2026
1 check passed
@projectdelta6
projectdelta6 deleted the chore/scrub-internal-references branch August 27, 2026 08:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant