Secret Leak Incident Response: Quick response is critical. Steps: 1) IMMEDIATE (1-5 min): a) Change DB password, b) Revoke GitHub repo access (check collaborators), c) Enable GitHub secret scanning alert if available (Settings → Security → Secret scanning), 2) SHORT TERM (5-30 min): a) Clean git history (BFG Repo-Cleaner: bfg --delete-files 'config.yml' — rewrite history), b) Force push (git push --force-with-lease) — WARNING: Team coordination required, c) Check other repos (grep -r password *.git), 3) REVIEW (30-60 min): a) Check git log (who pushed, when), b) Access logs (DB): any suspicious login attempts?, c) Check AWS CloudTrail, GCP Cloud Audit Logs, 4) NOTIFICATION: a) Inform team (git rewrite warning, rebase needed), b) DB team (password rotation). Prevention tools: 1) .gitignore (exclude config files), 2) env vars (.env, git-ignored), 3) GitHub secret scanning (built-in + third-party: TruffleHog, GitGuardian), 4) commit hooks (pre-commit framework: detect secrets before commit), 5) automated scanning (CI/CD: scan commits for patterns). Risk mitigation: DB access logs (suspicious IPs, query patterns), API rate limiting (prevent brute force), DB MFA (if supported).