> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wednesdayai.dev/llms.txt
> Use this file to discover all available pages before exploring further.

> Secrets, placeholders, secret scanning, dependency and patch policy, and local credential files

# Secure development

# Secure development

This guide covers the practices contributors follow while writing code. For reporting a vulnerability, the trust model and operator hardening, see the Security section of the docs site.

## Secrets and placeholders

* Never commit real phone numbers, API tokens, videos, or live config values. Use obviously fake placeholders.
* Docs content must be generic. Do not include personal device names, hostnames, or paths. Use placeholders such as `user@gateway-host`.
* Read the security policy before any security triage or advisory work.

## Local credential files

* Web provider credentials live in `~/.openclaw/credentials/`. Rerun `wednesdayai login` if you are logged out.
* Pi and agent sessions live in `~/.openclaw/agents/<agentId>/sessions/*.jsonl` (newest by default).

Never copy these into the repository, a fixture, or a log entry.

## Security scanning

The project uses `detect-secrets` for automated secret detection in CI. See `.detect-secrets.cfg` for configuration and `.secrets.baseline` for the baseline.

Run it locally:

```bash theme={"dark"}
pip install detect-secrets==1.5.0
detect-secrets scan --baseline .secrets.baseline
```

## Dependency policy

* Dependencies listed in `pnpm.patchedDependencies` must use exact versions (no `^` or `~`). Patching a dependency requires explicit approval.
* `@sinclair/typebox` is pinned to an exact version for the same reason.
* Never update the Carbon dependency (`@buape/carbon`).
* Never use `npm link` or `pnpm link` for local installs. Build with `npm pack` and install the tarball globally.

## Related

* [Coding style](/developers/contributing/coding-style)
* [Release](/developers/contributing/release)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.