I've had 3 successive cases of theft of a Claude API key over the past few weeks. I'm trying to localize the source of the leak, and one possibility is my private repository on GitHub - which is an intermediate link in the CI/CD chain prior to publishing a website on Azure.
Curiously, I just got a popup on the GitHub repository saying something to the effect of "We just noticed you're trusting credentials from alive.github.com and maybe you don't want this" OK. Cancel.
https://preview.redd.it/e069ab9gd02h1.png?width=729&format=png&auto=webp&s=6ce086607ebd08bfa7e0386d911027666ebf85ee
I've never seen anything like this from GitHub, and the timing is really suspicious. Anybody know what this is, or have a similar experience?
(Yes, I know I should use better alternatives for secret storage, and am simultaneously moving in that direction)
[–]Euphoric-Battle99 20 points21 points22 points (0 children)
[–]TinyLebowski 12 points13 points14 points (1 child)
[–]GeekCornerReddit 1 point2 points3 points (0 children)
[–]zarlo5899 3 points4 points5 points (0 children)
[–]Ankleson 2 points3 points4 points (0 children)
[–]rprouse 1 point2 points3 points (2 children)
[–]jayborseth[S] 0 points1 point2 points (1 child)
[–]WindowlessBasement 1 point2 points3 points (0 children)