Skip to content
Rush Commerce
Software & Dev2 min read

GitHub secret scanning now catches Lovable and Supabase keys

GitHub secret scanning added detectors for Lovable, Supabase, and Pydantic tokens. If you vibe-coded an app into a repo, here's what to check today.

GitHub secret scanning now detects API keys and tokens from Lovable, Supabase, and Pydantic. The October 5 changelog is short. The point is not. These are the keys that end up in repos built fast with AI app builders, by people who have never rotated a credential.

What actually happened

Per GitHub's changelog, five new secret types:

  • Lovable Labs: lovable_api_key. Lovable joined GitHub's secret scanning partner program. When one of these keys shows up in a public repo, GitHub reports it to Lovable automatically.
  • Supabase: supabase_oauth_access_token and supabase_scoped_personal_access_token.
  • Pydantic: logfire_token and pydantic_ai_gateway_api_key.
  • Where alerts fire. The four non-partner detectors raise alerts in both public and private repositories.

The changelog does not say whether push protection blocks these types yet, or whether GitHub checks if a found key is still valid. We would not assume either.

Why it matters for your business

Lovable, Supabase, and similar tools let a non-developer ship a working app in a weekend. Many of those apps get exported to GitHub. Keys get pasted into a config file "for now." That file gets committed. The repo goes public for a demo.

A Supabase personal access token is not a minor leak. Depending on its scope, it can reach your project, your database, and your customers' rows. The Supabase row-level security problem already showed how much of this data is exposed. Leaked tokens make it worse.

What we'd do this week:

  1. Turn on secret scanning for every repo you own, private ones included. Check the Security tab for alerts, including old ones.
  2. Rotate first, then clean history. Removing a key from the latest commit does nothing. It is still in Git history. Revoke it at the provider, issue a new one, then scrub.
  3. Move keys to environment variables. In Vercel, Netlify, or Supabase's own settings. Not in .env files you commit.
  4. Scope tokens down. A scoped token that can read one project does far less damage than a full-account token.

Key takeaways

  • GitHub secret scanning added Lovable, Supabase, and Pydantic detectors on October 5
  • Lovable is now a partner: its keys found in public repos get reported to Lovable
  • Supabase and Pydantic detectors alert in public and private repos
  • Push protection and validity checks for these types were not stated
  • If a key leaked, revoke and rotate it before you clean Git history

Built your app in Lovable and not sure what's in the repo? We audit vibe-coded apps for leaked keys, open databases, and missing access rules, then fix them so you own a codebase you can trust. See our services or send us the repo.

Sources: GitHub Changelog: Secret scanning adds detectors for Lovable, Supabase, and more.

  • #github
  • #secret-scanning
  • #lovable
  • #supabase
  • #api-keys
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.