Skip to content

Commit 3b0bda0

Browse files
author
Deepak Pandey
committed
security: Remove unnecessary Supabase secrets from Lighthouse CI step
- Remove NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_ANON_KEY, and SUPABASE_SERVICE_ROLE_KEY - These environment variables are not used by lhci command - Follows principle of least privilege to prevent accidental exposure - Service role key should never be present in client contexts
1 parent 1aed9f2 commit 3b0bda0

File tree

1 file changed

+0
-3
lines changed

1 file changed

+0
-3
lines changed

.github/workflows/ci-cd.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -595,9 +595,6 @@ jobs:
595595
LHCI_GITHUB_APP_TOKEN: ${{ secrets.LHCI_GITHUB_APP_TOKEN }}
596596
LHCI_TOKEN: ${{ secrets.LHCI_TOKEN }}
597597
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
598-
NEXT_PUBLIC_SUPABASE_URL: ${{ secrets.NEXT_PUBLIC_SUPABASE_URL }}
599-
NEXT_PUBLIC_SUPABASE_ANON_KEY: ${{ secrets.NEXT_PUBLIC_SUPABASE_ANON_KEY }}
600-
SUPABASE_SERVICE_ROLE_KEY: ${{ secrets.SUPABASE_SERVICE_ROLE_KEY }}
601598

602599
- name: Upload performance results
603600
uses: actions/upload-artifact@v4

0 commit comments

Comments
 (0)