Comment by neandrake
They first disabled rubocop to prevent further exploit, then rotated keys. If they awaited deploying the fix that would mean letting compromised keys remain valid for 9 more hours. According to their response all other tools were already sandboxed.
However their response doesn't remediate putting secrets into environment variables in the first place - that is apparently acceptable to them and sets off a red flag for me.
"According to their response all other tools were already sandboxed."
Everything else was fine, just this one tool chosen by the security researcher out of a dozen of tools was not sandboxed.