Skip to content

security(cosds): redact leaked AppSync API key from api-testing docs - #54

Merged
NetworkTheoryAppliedResearchInstitute merged 1 commit into
mainfrom
security/cosds-redact-appsync-key
Sep 14, 2026
Merged

NetworkTheoryAppliedResearchInstitute merged 1 commit into
mainfrom
security/cosds-redact-appsync-key

Conversation

@NetworkTheoryAppliedResearchInstitute

Copy link
Copy Markdown
Contributor

COSDS secret-leak remediation (2026-08-11)

Today's COSDS scan found a real AWS AppSync API key hard-coded in the API testing playbook — the same key that was committed to Agrinet and fruitful.

Changes

Replace the literal key with the doc's existing <your-key> placeholder in:

  • docs/api-testing.md (lines 26 & 108)
  • versioned_docs/version-1.1.0/api-testing.md
  • versioned_docs/version-1.1/api-testing.md

⚠️ Does not un-leak

The key remains in git history (and in built assets in history). A coordinated history purge across the affected repos will follow. Rotate the AppSync key if that GraphQL API is still live.

Filed as part of COSDS. Companion PR: NTARI-RAND/Agrinet#146.

COSDS secret-leak review (2026-08-11) found a real AWS AppSync API key
embedded in the API testing playbook (and its versioned copies). Replace
the literal key with the doc's existing `<your-key>` placeholder.

- docs/api-testing.md
- versioned_docs/version-1.1.0/api-testing.md
- versioned_docs/version-1.1/api-testing.md

Note: the key remains in git history; a coordinated purge will follow, and
the key should be rotated if the AppSync API is still live.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: NetworkTheoryAppliedResearchInstitute <info@ntari.org>
@csecrestjr
csecrestjr self-requested a review August 30, 2026 11:59
@NetworkTheoryAppliedResearchInstitute
NetworkTheoryAppliedResearchInstitute merged commit fc51719 into main Sep 14, 2026
5 checks passed
@NetworkTheoryAppliedResearchInstitute
NetworkTheoryAppliedResearchInstitute deleted the security/cosds-redact-appsync-key branch September 14, 2026 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants