binary-husky / binary-husky/gpt_academic
Security Notice: Exposed HuggingFace API key detected
- Dominant language
- Python
- Stars
- 71.3k
- Forks
- 8.3k
- PR merge metrics
- No merged PRs in 30d
Description
Hi there,
We found an exposed HuggingFace API key in this repository (ending in ...JmAV).
**What happened:** Your API key was committed to a public file and is visible to anyone. It has been viewed 5,840 times.
**Recommended steps:**
1. Revoke or rotate this key immediately
2. Check your billing dashboard for unexpected charges
3. Generate a new key and store it in environment variables or a secrets manager
4. Add your key patterns to a `.gitignore` or use tools like `git-secrets` to prevent future leaks
This was detected by [Unsecured API Keys](https://unsecuredapikeys.com), a security awareness tool that scans public repositories for accidentally exposed credentials.
Stay safe out there.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by revoking or rotating the exposed HuggingFace key and checking the repository's public files and history for the leaked credential. The issue names no specific file or test; done means the key is invalidated, the secret is removed from reachable repository content where possible, and future exposure is addressed with environment variables, a secrets manager, .gitignore, or git-secrets.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- git, huggingface
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100