Fix env validation#2147
Open
Kavyamanchanpally wants to merge 2 commits into
Open
Conversation
|
@Kavyamanchanpally is attempting to deploy a commit to the PRIYANSHU DOSHI's projects Team on Vercel. A member of the Team first needs to authorize it. |
GSSoC Label Checklist 🏷️@Priyanshu-byte-coder — please apply the appropriate labels before merging: Difficulty (pick one):
Quality (optional):
Validation (required to score):
|
Owner
|
This PR now has a merge conflict with git fetch origin
git rebase origin/main |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Added build-time environment validation to prevent accidental exposure of sensitive credentials during production builds.
Closes #1462
Type of Change
Changes Made
Added
scripts/validate-env.jsfor environment variable validationAdded a new
validate-envnpm scriptUpdated the build process to run validation before
next buildDetects sensitive environment variables such as:
private_keysecretsupabase_secretgithub_tokentokenpasswordapi_keyBlocks the build when sensitive credentials are detected
Displays clear validation messages during build execution
How to Test
Steps for the reviewer to verify this works:
Run:
Verify validation passes when no sensitive environment variables are present.
Add a sensitive environment variable (example):
Run:
Verify the build is blocked and an error message is displayed.
Remove the sensitive variable and run:
Verify the application builds successfully.
Checklist
npm run buildpasses successfullySecurity Checklist
Additional Notes
This change adds an additional security layer to the build pipeline by preventing accidental inclusion of sensitive credentials in production builds.