No qualifying production incident has been recorded for this repository as of
2026-07-12. An issue labeled incident and sev1 through sev4 opens the process
in OPERATIONS.md. Closing an incident requires a committed
YYYY-MM-DD-short-title.md postmortem that links the issue and records the UTC
timeline, impact, detection, root cause, and owned actions.
Secret exposure uses the dedicated rotate, revoke, containment, history-scrub decision, and notification sequence in the operations runbook. A missing postmortem is a release blocker, not an undocumented exception.