Comment by tadfisher
But do you still store your GH API private key in environment variables?
But do you still store your GH API private key in environment variables?
So the CodeRabbit application with access to application secrets still runs in the same virtual machine as untrusted code from the outside?
hey, this is Howon from CodeRabbit. We use a cloud-provider-provided key vault for application secrets, including GH private key.