GitHub secret scanning now catches Lovable and Supabase keys
GitHub secret scanning added detectors for Lovable, Supabase, and Pydantic tokens. If you vibe-coded an app into a repo, here's what to check today.
GitHub secret scanning now detects API keys and tokens from Lovable, Supabase, and Pydantic. The October 5 changelog is short. The point is not. These are the keys that end up in repos built fast with AI app builders, by people who have never rotated a credential.
What actually happened
Per GitHub's changelog, five new secret types:
- Lovable Labs:
lovable_api_key. Lovable joined GitHub's secret scanning partner program. When one of these keys shows up in a public repo, GitHub reports it to Lovable automatically. - Supabase:
supabase_oauth_access_tokenandsupabase_scoped_personal_access_token. - Pydantic:
logfire_tokenandpydantic_ai_gateway_api_key. - Where alerts fire. The four non-partner detectors raise alerts in both public and private repositories.
The changelog does not say whether push protection blocks these types yet, or whether GitHub checks if a found key is still valid. We would not assume either.
Why it matters for your business
Lovable, Supabase, and similar tools let a non-developer ship a working app in a weekend. Many of those apps get exported to GitHub. Keys get pasted into a config file "for now." That file gets committed. The repo goes public for a demo.
A Supabase personal access token is not a minor leak. Depending on its scope, it can reach your project, your database, and your customers' rows. The Supabase row-level security problem already showed how much of this data is exposed. Leaked tokens make it worse.
What we'd do this week:
- Turn on secret scanning for every repo you own, private ones included. Check the Security tab for alerts, including old ones.
- Rotate first, then clean history. Removing a key from the latest commit does nothing. It is still in Git history. Revoke it at the provider, issue a new one, then scrub.
- Move keys to environment variables. In Vercel, Netlify, or Supabase's own settings. Not in
.envfiles you commit. - Scope tokens down. A scoped token that can read one project does far less damage than a full-account token.
Key takeaways
- GitHub secret scanning added Lovable, Supabase, and Pydantic detectors on October 5
- Lovable is now a partner: its keys found in public repos get reported to Lovable
- Supabase and Pydantic detectors alert in public and private repos
- Push protection and validity checks for these types were not stated
- If a key leaked, revoke and rotate it before you clean Git history
Built your app in Lovable and not sure what's in the repo? We audit vibe-coded apps for leaked keys, open databases, and missing access rules, then fix them so you own a codebase you can trust. See our services or send us the repo.
Sources: GitHub Changelog: Secret scanning adds detectors for Lovable, Supabase, and more.
- #github
- #secret-scanning
- #lovable
- #supabase
- #api-keys
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
GitHub stacked pull requests GA: review AI code in small pieces
GitHub stacked pull requests are now GA on all plans, with the gh stack CLI and merge queue support. Why small PRs matter more when agents write code.
Read itAnthropic Cyber Verification Program: 3 tiers, ask your MSP
Anthropic's expanded Cyber Verification Program opens Mythos-class security AI to small security firms in three tiers. What it means if you buy security, not sell it.
Read it