deckhearth/.github/workflows
varutasu 8c58990fd9
fix(security): stop leaking Gemini API key to browsers (#34)
Delete the public /api/config/gemini endpoint and remove client auto-load
paths so GEMINI_AI_API_KEY stays server-side only. Add a scan rate-limit
class for the upcoming server-side identify route and a CI gate that blocks
reintroducing config key leaks or new browser LLM URLs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-27 08:41:48 -05:00
..
agent-context-drift.yml bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00
ci.yml fix(security): stop leaking Gemini API key to browsers (#34) 2026-05-27 08:41:48 -05:00
pr-health-rollup.yml bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00
preview-smoke.yml fix(ci): plumb VERCEL_AUTOMATION_BYPASS_SECRET into preview-smoke + visual-diff (#17) 2026-05-24 16:26:22 -05:00
visual-diff.yml ci(workflows): exclude pages/api/** from visual-diff path filter (#26) 2026-05-26 22:51:22 -05:00