Skip to content

Removes the CI step that posted full output as a comment#22

Merged
mcrundo merged 1 commit into
mainfrom
remove-plan-pr-comment
Apr 17, 2026
Merged

Removes the CI step that posted full output as a comment#22
mcrundo merged 1 commit into
mainfrom
remove-plan-pr-comment

Conversation

@mcrundo
Copy link
Copy Markdown
Owner

@mcrundo mcrundo commented Apr 17, 2026

Summary

Removes the CI step that posted full terraform plan output as a comment on every PR. During a recent
incident, this step surfaced plaintext values of Lambda environment variables (Google Maps API key and
service API key) in public PR comments and Actions logs, triggering an automated key-exposure alert from
Google. Also tightens .gitignore so bare-named local plan files (e.g. terraform/tfplan) cannot
accidentally be committed.

@mcrundo mcrundo merged commit 2ed9a1f into main Apr 17, 2026
4 checks passed
@mcrundo mcrundo deleted the remove-plan-pr-comment branch April 17, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant