My API key leaked in a public repo on Tuesday and I had no idea for 2 days
Pushed a test script to a public GitHub repo on Tuesday morning and forgot it had my Stripe key hardcoded in it. A bot found it in under 10 minutes and started hitting my endpoint, and I didn't notice until my usage alerts blew up on Thursday with about 4,000 weird requests. I rotated the key right away but the charges already went through, something like $230. Now I'm wondering what else I should be doing besides just keeping keys in env files, like do you all use any scanning tools or pre-commit hooks that catch this stuff before it gets pushed?