BloomTech-Labs / betterreads-ds

MIT License
1 stars 3 forks source link

Git Secrets #41

Open michael-rowland opened 4 years ago

michael-rowland commented 4 years ago

Currently, the master branch reads environment variables from a local .env file. However, if you know where to look, deep enough in the commit history, there are API keys exposed. These are the ones I could find after a quick search, but there are likely many more:

We didn't have time to clean this up. One tool that was mentioned by the Labs staff was Git Secrets, which may be useful in solving this issue.