Skip to content

security: untrack .env.bak-2026-07-28, widen the env gitignore - #164

Closed
ralyodio wants to merge 1 commit into
masterfrom
worktree-scrub-env-backup
Closed

ralyodio wants to merge 1 commit into
masterfrom
worktree-scrub-env-backup

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Superseded by #166 (identical diff, credential detail kept out of the PR text). Closed.

The file is a verbatim dump of a production environment — 21 secrets by
gitleaks' count, including SUPABASE_SERVICE_ROLE_KEY, SUPABASE_DB_PASSWORD,
GITHUB_APP_PRIVATE_KEY, SOCIAL_VAULT_KEY, NEXT_SERVER_ACTIONS_ENCRYPTION_KEY,
CRON_SECRET, WORKER_SHARED_SECRET, SP_TOKEN_PEPPER and a dozen third-party
API keys. It has been on master since 925da5e (#160, 2026-07-28), so the
gitleaks job has been failing every PR since.

The old ignore list named each env variant explicitly — .env, .env.local,
.env.development and so on — so a .env.bak-<date> matched none of them.
Replaced with `.env*` plus a negation for the checked-in .env.example, which
fails closed instead of open.

This stops further exposure and makes the scan pass. It does NOT unleak
anything: the values are in the pushed history and must be treated as
compromised. Every credential in that file needs rotating.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio ralyodio closed this Jul 30, 2026
@ralyodio
ralyodio deleted the worktree-scrub-env-backup branch July 30, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant