My API key sat in a public GitHub repo for 9 days and the log showed someone probing it
Pushed a side project to a public repo last Tuesday and forgot a .env line, and a bot found the key in under an hour. Anyone got a favorite way to scan repos before pushing, or do you just run git-secrets and hope?