Skip to content

security: remove committed service-account credential and harden secret hygiene - #5

Draft
Shambez with Copilot wants to merge 2 commits into
mainfrom
copilot/improve-secret-handling
Draft

security: remove committed service-account credential and harden secret hygiene#5
Shambez with Copilot wants to merge 2 commits into
mainfrom
copilot/improve-secret-handling

Conversation

Copilot AI commented Jun 5, 2026

Copy link
Copy Markdown

Root-level google-services.json contained a Firebase Admin SDK service-account private key and was tracked in git. This cleans it up and adds guardrails to prevent recurrence.

Changes

  • Removed google-services.json (root) — service-account credential ("type": "service_account" with private_key, client_email). The legitimate Android client config at android/app/google-services.json is unaffected.
  • .gitignore — added explicit block patterns for server-side credential files:
    google-services.json        # root only; android/app/ is still allowed
    service-account*.json
    firebase-admin*.json
    *.p8 / *.pem / *.key / *.cer / *.mobileprovision
    
    Removed duplicate .env / .env.* lines; !.env.example exception preserved.
  • .env.example — placeholder for all four EXPO_PUBLIC_* vars referenced in app.config.js, with an explicit comment that EXPO_PUBLIC_* values are client-bundled and must not carry private server secrets.
  • SECRETS.md — concise reference covering: what never to commit, EXPO_PUBLIC_* vs true secrets distinction, local dev setup, EAS/CI secret injection, and a reminder to rotate any previously exposed credentials.

⚠️ The Firebase service-account key that was tracked should be rotated regardless of whether the private key content was real — treat any committed credential as compromised.

Original prompt

Prepare a pull request in Shambez/SimbaGlobal_AI to improve secret handling and reduce the risk of committed credentials.

Make these exact changes:

  1. Tighten .gitignore

    • Keep ignoring .env and .env.* while still allowing .env.example.
    • Add ignores for dangerous server-side credential files and other local secret artifacts, including patterns such as:
      • google-services.json at repo root
      • service-account*.json
      • firebase-admin*.json
      • *.p8
      • *.mobileprovision
      • *.pem
      • *.key
      • *.cer
    • Preserve intended tracked platform client config files if they are still needed, but do not allow obviously dangerous root-level server credential files.
    • Avoid overly broad patterns that would break the app.
  2. Add .env.example

    • Include non-secret placeholders for the environment variables currently referenced by the app config and related setup.
    • At minimum include placeholders for:
      • EXPO_PUBLIC_APP_ENV
      • EXPO_PUBLIC_API_URL
      • EXPO_PUBLIC_OPENAI_PROJECT_ID
      • EXPO_PUBLIC_PICOVOICE_ACCESS_KEY
    • Add short comments clarifying that EXPO_PUBLIC_* variables are bundled into the client and must not contain private server secrets.
  3. Remove dangerous tracked secret file(s)

    • Remove the dangerous tracked root-level google-services.json if present and if it contains service-account/private-key style credentials rather than Android client config.
    • Do not remove legitimate Android client config at android/app/google-services.json unless clearly unsafe.
    • If there are other obviously dangerous tracked secret files discovered while implementing, remove them too.
  4. Add a short SECRETS.md setup guide

    • Explain what must never be committed.
    • Explain the difference between public Expo client env vars (EXPO_PUBLIC_*) and true secrets.
    • Give concise instructions for local development and CI/EAS secret handling.
    • Mention that previously committed secrets should be rotated.

Implementation notes:

  • Keep the changes minimal and focused.
  • If any code or docs reference the removed root google-services.json, update them so the repo remains coherent.
  • Open a pull request with a concise title and summary of the security cleanup.

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: help secure and hide my secrets

Assistant: Yes — you should treat this repo as potentially exposed and rotate secrets now.

What I found:

  • Your repo currently tracks a root-level google-services.json, and the version I inspected contains service-account style fields like private_key, client_email, and client_id. That is a real secret pattern, not something that should live in a public repo.
  • Your .gitignore explicitly allows Firebase config files:
    • !android/app/google-services.json
    • !GoogleService-Info.plist
    • !ios/**/GoogleService-Info.plist
  • Your Expo config already reads runtime values from environment variables:
    • EXPO_PUBLIC_API_URL
    • EXPO_PUBLIC_OPENAI_PROJECT_ID
    • EXPO_PUBLIC_PICOVOICE_ACCESS_KEY

Immediate actions

  1. Revoke/rotate the Firebase service account key used in google-services.json.
  2. Check whether this repo is public. If yes, assume compromise.
  3. Remove committed secret files from the repo and history.
  4. Move secrets into environment variables / secret managers.
  5. Keep only safe client config files in git.

Important distinction

Some files are okay to commit:

  • android/app/google-services.json for Firebase client app config is often okay
  • GoogleService-Info.plist is often okay

But the file you have at the repo root looks like a server/service account credential, which is not okay to commit.

Recommended repo changes

  • Delete root google-services.json
  • Ignore server credential files like:
    • google-services.json at repo root
    • service-account*.json
    • firebase-admin*.json
    • .env.local, .env.production, etc.
  • Keep only an example file:
    • .env.example

Safer pattern for this Expo app

Use:

  • EXPO_PUBLIC_* only for values safe to expose to the client
  • non-public secrets only in:
    • EAS Secrets
    • GitHub Actions Secrets
    • server-side environment variables
    • Firebase Functions config / cloud secret manager

Do not put these in the mobile app

  • OpenAI secret API keys
  • Firebase Admin SDK private keys
  • Stripe secret keys
  • any private signing credentials

Your current config looks mostly fine here

app.config.js is already using env vars instead of hardcoding keys, which is the right direction.

What I can do next

I can help you clean this up in the repo by preparing exact changes:

  1. tighten .gitignore
  2. add .env.example
  3. remove the dangerous tracked secret file(s)
  4. add a short SECRETS.md setup guide

If you want, I can make those edits for Shambez/SimbaGlobal_AI and open...

This pull request was created from Copilot chat.

Copilot AI changed the title [WIP] Improve secret handling and reduce risk of committed credentials security: remove committed service-account credential and harden secret hygiene Jun 5, 2026
Copilot AI requested a review from Shambez June 5, 2026 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants