Do not commit DataHub tokens, customer metadata, or production certificates. Use environment variables for credentials and read-only tokens for scans.
Report suspected vulnerabilities privately to the project maintainers rather than opening a public issue with exploit details.