Repository navigation
security: remove hardcoded Infura API key from debug scripts - #363
Merged
Merged
Conversation
check-account.js and test-userop-hash.js hardcoded a Sepolia Infura API key in the RPC URL. Replaced with process.env.ETH_RPC_URL (public-RPC fallback) so the scripts still run without embedding a secret. NOTE: the key is already exposed in this public repo's git history (and was also present in an earlier ecosystem.config.js fallback), so it MUST be rotated in the Infura dashboard — removing it from the tree does not undo the exposure. The ETH_PRIVATE_KEY and Pimlico key that also appear in history must be rotated too.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Scans the repo for private keys / API keys on push + PR to main/master/develop (complements the local pre-commit hook). Installed via LeakShield.
scripts/security/scrub-history.sh purges the 3 leaked credentials from git history via git-filter-repo. Secrets are extracted from history at runtime (not hardcoded), written to a .git-local replacements file, and deleted after. Dry-run by default; --run rewrites history (then force-push + collaborators re-clone). Clearly marked: rotation is mandatory regardless — scrubbing a public repo's history does NOT undo the exposure.
clestons
approved these changes
Jun 24, 2026
clestons
left a comment
There was a problem hiding this comment.
clestons review — #363 [2-round, APPROVE]
security: remove hardcoded Infura API key from debug scripts — security housekeeping following the credentials exposure in #104. 4 files.
Verified ✅
- Key removal confirmed:
check-account.jsandtest-userop-hash.jsboth had-const RPC_URL = "https://sepolia.infura.io/v3/7051eb377c..."removed and replaced withprocess.env.ETH_RPC_URL(public-RPC fallback). No hardcoded secrets remain in these files. - CI secret scanner (
.github/workflows/check-secrets.yml): covers 8 generic patterns —0x[a-fA-F0-9]{64}(ETH private keys),BEGIN.*PRIVATE KEY(PEM),AKIA…(AWS),sk-…(OpenAI/Anthropic),gh[pousr]_…(GitHub PAT),sk_(live|test)_…(Stripe),api_key = "..."— this is broad coverage, not just these specific leaked keys. Future leaks will be caught generically. scrub-history.sh: correctly notes that tree-removal is not enough and provides git-filter-repo instructions. PR body includes explicit rotation guidance for all 3 credentials.- Secret scan of this PR itself: clean.
Note (Info): scrub-history.sh mentions 0x075F227E… but the leaked private key was 0x72966a3f…. Verify the correct key is used in the git history scrub command.
APPROVE. Keys correctly replaced with process.env references; CI scanner adds ongoing protection with generic patterns. Rotation of all 3 credentials (Infura / ETH_PRIVATE_KEY / Pimlico) remains a required out-of-band action.
…tes32)
LeakShield's 0x[a-fA-F0-9]{64} pattern can't distinguish a private key from a
legitimate bytes32 (hashes, storage slots, calldata, test fixtures) — it flagged
many false positives across the repo, making the check permanently red. Keeping
the Infura-key removal + history-scrub script here; the detection-quality fix
(context-aware matching) goes upstream to LeakShield first, then we re-adopt.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
aastar/check-account.jsandaastar/test-userop-hash.jshardcoded a Sepolia Infura API key inside the RPC URL. Replaced both withprocess.env.ETH_RPC_URL(public-RPC fallback) — the scripts still run, no secret embedded.This repo is public and the leaked credentials are already in git history (e.g. commits
ca83890, and an earlierecosystem.config.jsfallback now removed by4e736cb). Removing them from the tree does not undo the exposure. The following must be rotated/revoked out-of-band:7051eb37…— rotate in Infura0x72966a3f…— revoke + move any funds (in history)pim_gcVkL…— rotate in PimlicoSurfaced by the PR-daemon review of #104 (already merged). Current
ecosystem.config.jsis already clean (readsprocess.env); this PR clears the last in-tree copy.