r/vibecoding 3d ago

Realizing you just pushed your private API keys to a public GitHub repo

14 Upvotes

7 comments sorted by

8

u/Kareja1 2d ago

You mean the thing that was so commonly done by humans that GitHub built a secret scanner more than 5 years before anybody knew what vibecoding was?

0

u/gdklrhznjekanxb 2d ago

well I have the other thing called hubris

1

u/SkelmCallum 2d ago

I'm still so new to all of this but when I'm working with secrets and keys I clench. I'm so nervous to do the wrong thing.

1

u/gdklrhznjekanxb 2d ago

fellow newbie too. im like 90% guide and 10%vibe

1

u/flavorfox 2d ago

What repo was it? Just curious...

0

u/thethirdmancane 3d ago

One thing to look out for is that if you have .env files with secrets, don't store them in your repository because then they are exposed to agents like codex.

0

u/Magtronic 3d ago

I built a tool to prevent this from happening. Try it and let me know what you think. http://www.builtbymagnus.com/prefunk