Skip to content

Possible exposed credential in this repo #6

Description

@Product-nomad

Hi — while doing some public-good scanning for exposed secrets in public repos, I think I spotted a live-looking OpenSSH private key in private.pem (commit 1082ddc).

I haven't accessed, tested, or used it, and I'm not going to.

What I'd suggest:

  1. Rotate/revoke this credential with the provider immediately
  2. Remove it from git history (not just the latest commit — it's still in the log): how to remove sensitive data from a repository
  3. Move secrets to environment variables or a .gitignored file going forward

No action needed from me — feel free to close this issue once handled.


Flagged by PublicGuard, an open, non-commercial scan run as part of my security tooling work (companion to SessionGuard). Happy to answer questions, no strings attached.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions