fix(security): remove leaked Forgejo credential and stray Python artifacts #695
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/remove-leaked-credential-artifacts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
An earlier commit (
542469a3) swept a git-credential-fill output file (cred.txt, containing a live Forgejo token) into the tree alongside scratch Python scripts (api.py, logs.py, open_pr.py, and friends) used to drive Forgejo/Binjovi from the command line. Both violate this repo's own rules: never commit secrets, and never use Python here.The leaked token has already been rotated (
make forgejo-cred). This PR only removes the tracked artifacts and hardens.gitignoreagainst the same failure mode (cred.txt/cred.in,__pycache__/*.pyc,*.out) so a future broadgit addcan't reintroduce them.tests/binjovi.sh, the guard covering the same manifests these stray files landed alongside, still passes unchanged.https://claude.ai/code/session_01JGe4pyhQ36AhgDfPJry4d3