GitHub secret scanning now catches leaked Lovable API keys and Supabase access tokens
As of Oct 5, secret scanning flags lovable_api_key, Supabase OAuth and scoped personal access tokens, and Pydantic Logfire and AI Gateway keys in your repos, and Lovable joined the partner program, so a Lovable key pushed to a public repo gets sent to Lovable to revoke or rotate. If your agent ever committed a .env, check your repo's security alerts.