binary-husky / binary-husky/gpt_academic

Security Notice: Exposed HuggingFace API key detected

Open
#2,261 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
71.3k
Forks
8.3k
PR merge metrics
No merged PRs in 30d

Description

Hi there,

We found an exposed HuggingFace API key in this repository (ending in ...JmAV).

**What happened:** Your API key was committed to a public file and is visible to anyone. It has been viewed 4,085 times.

**Recommended steps:**
1. Revoke or rotate this key immediately
2. Check your billing dashboard for unexpected charges
3. Generate a new key and store it in environment variables or a secrets manager
4. Add your key patterns to a `.gitignore` or use tools like `git-secrets` to prevent future leaks

This was detected by [Unsecured API Keys](https://unsecuredapikeys.com), a security awareness tool that scans public repositories for accidentally exposed credentials.

Stay safe out there.

Contributor guide

No contributing guide indexed for this repository

Research direction

No repository file, test, or entry point is identified. Start by locating the exposed HuggingFace key in the repository and its public history, then follow the notice's steps to revoke or rotate it, check billing, and prevent future exposure; done means the credential is invalidated and no longer publicly accessible.

Written by the indexing model from the issue text.

Assessment

Tech stack
huggingface
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.