security: redact leaked Supabase credential from .env.example#2
Merged
Conversation
backend/.env.example committed a real Supabase transaction-pooler connection string (project ref + password), not a placeholder. A .env.example must only show the format. Replaced it with a commented template; a fresh clone now uses the local POSTGRES_* defaults. NOTE: the credential remains in git history — rotating the Supabase database password is a required manual follow-up (see PR description).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue (found during RC-1 audit)
backend/.env.exampleshipped a real Supabase transaction-pooler connection string (project ref + password) instead of a placeholder. It is committed to a public repo.Fix
Replaced the concrete
DATABASE_URLwith a commented format template. A fresh clone now falls back to the localPOSTGRES_*defaults; the Supabase pooler format is documented without real values. No application logic changed.Redacting the file does not remove the credential from git history. The repository owner must:
git filter-repo/ BFG) — note this rewrites history and needs a force-push, so decide deliberately.🤖 Generated with Claude Code