Secret scanning false positives and misses: rule tuning and repo cleanup

Secret scanning false-positive and miss playbook: tell fake keys from real leaks, configure allowlists and suppression TTLs, and always rotate credentials before rewriting history. For security and DevOps — clear warnings on force-push and other dangerous ops, cut noise without leaving backdoors. Where uncertain, follow official docs and the current product version; do not assume undelivered capabilities.