Hacker News new | ask | show | jobs
by TurdF3rguson 99 days ago
Ok I see, so any public gist with an algolia key in it will get invalidated? And it would have to follow some pattern like ALGOLIA_KEY=xxx ?
1 comments

it works for any gist, public or private. it doesn't need to follow a certain format. it's just based on how the secret itself is formatted—it works for secrets that have a predictable pattern, like the AWSK prefix for Amazon keys.

if algolia keys have this predictable pattern, then they can enroll in secret scanning. If they don't then they probably can't