
Image: GitHub
Why it mattersPushing an API key for one of these services to a public repository will trigger an automatic revocation from the vendor before an attacker can use it.
A hard-coded API key for a popular service used to sit in a public commit until somebody noticed it. GitHub added detectors on 5 October for five more secret types, and for one of them the key is now cancelled by the vendor before most people notice.
The changelog lists five new patterns: lovable_api_key from Lovable Labs, logfire_token and pydantic_ai_gateway_api_key from Pydantic Services, and supabase_oauth_access_token and supabase_scoped_personal_access_token from Supabase. Any one of these pushed to a public repository will now set off secret scanning.
What auto-revoke means in practice
GitHub divides the detectors into two groups. Partner secrets, meaning secrets from a service that has joined its partnership programme, are reported straight to the issuer when found in a public repository, and the issuer can revoke the key before it can be used. User secrets instead generate an alert for the repository owner to deal with by hand, and this applies to public and private repositories.
The one new partner here is Lovable Labs. A lovable_api_key pushed to a public commit is now sent to Lovable, which can rotate it in place. The Pydantic and Supabase keys are user secrets, so they produce an alert and nothing is cancelled automatically, which means the developer still has to rotate the key before it is used.
The practical gap
The partner path works only on public repositories, which GitHub states in the same sentence. A key in a private repository is still a secret the organisation has to find and remove itself.
The detectors also catch only the exact patterns the vendor publishes. A dotenv file renamed in a way that hides the key format, a key split across two lines, or a key written in a comment with no quotes may slip through. Secret scanning is a backstop, not a replacement for keeping secrets out of commits in the first place.
For a team already using these services, nothing changes in the workflow: GitHub turns the new detectors on without any setting to flip. For a team planning to use Lovable, Supabase or Pydantic in a public repository, the key classes above are the ones to pattern-match in a pre-commit check.
Three names stand out in the list because of how they are used today. Lovable builds applications from a prompt, so a lovable_api_key sitting in a committed example gives a stranger the right to generate on the team's account. Supabase is a database back end, and its OAuth and scoped access tokens let the holder call the project's APIs. A Pydantic AI gateway key can send paid LLM traffic through the team's own account. Each is the kind of key a developer sees in a quick-start guide and copies into source control without a second thought.
A reader with a Lovable or Supabase account can test the behaviour by searching the repository for every file that might include one of the new patterns before the next push. GitHub's documentation lists the full set of supported secrets alongside today's additions.
Source
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.

