Skip to content

Correct the secrets job comment about the history finding - #9

Merged
zerotrustdavid merged 1 commit into
mainfrom
main-s6rx8d
Aug 22, 2026
Merged

Correct the secrets job comment about the history finding#9
zerotrustdavid merged 1 commit into
mainfrom
main-s6rx8d

Conversation

@zerotrustdavid

Copy link
Copy Markdown
Owner

The comment explaining why the secrets job does not scan full history
described the Web3Forms access key in this repository's history as
"already rotated". It was not rotated, and it is not going to be.

The key remains live. Its continued exposure is a deliberately accepted
risk, on the basis that Web3Forms treats the value as the form's own
identifier and publishes it to the browser by design, so the exposure
carries no account access and no confidentiality loss beyond what the
deployed site already discloses.

That distinction matters here more than in an ordinary stale comment.
The comment sits in a public file and is the stated justification for
the job's scope, so a reader auditing the repository would take it as
evidence the finding is closed. The accepted-risk position is
defensible on its own terms; the claim of remediation is not.

The same claim was corrected in .env.example and SECURITY.md in an
earlier change. This file was missed at the time and is the last place
stating it. The rest of the tree has been swept for the same claim and
for revoked, invalidated and regenerated; the only remaining hits
concern brand asset regeneration and are unrelated.

Comment-only change. No behaviour change to either job. The workflow
still parses to the same two jobs, verify and secrets, with the
same three steps in secrets.


Generated by Claude Code

The comment described the Web3Forms access key in this repository's
history as already rotated. It was not rotated. The key remains live and
its continued exposure is a deliberately accepted risk, on the basis that
Web3Forms treats the value as the form's own identifier and publishes it
to the browser by design.

The same claim was corrected in .env.example and SECURITY.md; this file
was missed at the time and is the last place stating it.
@vercel

vercel Bot commented Aug 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
payreckon Ready Ready Preview Aug 22, 2026 7:54pm

@zerotrustdavid
zerotrustdavid merged commit 1b1355a into main Aug 22, 2026
4 checks passed
@zerotrustdavid
zerotrustdavid deleted the main-s6rx8d branch August 27, 2026 06:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant