Skip to content

[Security] Revoke and remove tracked PurelyMail credentials #351

Description

@reacher-z

Problem

.env is tracked by Git and pyproject.toml force-includes it in wheel/sdist artifacts. The file contains a non-placeholder PurelyMail API key and must be treated as exposed.

Required scope

  • Revoke and rotate the current PurelyMail credential.
  • Remove .env from Git history and package inclusion; add a safe .env.example.
  • Load credentials only from CI/runtime secrets.
  • Add secret scanning and a release check that wheel/sdist artifacts contain no credentials.
  • Update Harbor/native documentation so credentials are injected, never packaged.

Acceptance criteria

  • git ls-files .env is empty.
  • Built wheel and sdist contain no .env or credential values.
  • CI fails on newly introduced secrets.
  • Historical release artifacts are audited and the rotation is documented.

This is tracked as SEC-001 in docs/codebase-evaluation-2026-09.md. @Perry2004 please review ownership and the rotation plan.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinghelp wantedExtra attention is needed

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions