Skip to content

[Security] Your minimax API key was committed to this repo #9

@cheesestudio

Description

@cheesestudio

Hey! Just a heads-up -- I ran a scan and it looks like an API key got committed to this repo, and it's still active.

Detail Value
Provider minimax
File activate-minimax.sh
Source https://github.com/indiamonda/indiamonda.github.io/blob/bde6b77b3577a131f89f9f3fa22bc6bbd856bca2/activate-minimax.sh

What's the risk?

The key is still live -- anyone who comes across it can use it, burning through your credits or quota.

What to do:

  1. Revoke the key in your minimax dashboard
  2. Generate a new key and swap it in
  3. Delete the key from the committed file and add .env to .gitignore
  4. Check your minimax usage logs for anything suspicious
  5. Scrub the key from git history with git filter-branch or BFG

Once you've sorted it out, just close this issue.


This is a free public-service scan. If it helped, you can buy me a coffee at https://ko-fi.com/cheeseup (no pressure at all).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions