-
Notifications
You must be signed in to change notification settings - Fork 17
Update cfg.py #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Reviewer's Guide by SourceryThe bot token was updated in the cfg.py file. No diagrams generated as the changes look simple and do not need a visual representation. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @Okliaopapapa - I've reviewed your changes and found some issues that need to be addressed.
Blocking issues:
- Do not commit bot tokens or other credentials directly in source code (link)
Overall Comments:
- SECURITY CRITICAL: Never commit API tokens or credentials directly in source code. This token has been exposed and should be revoked immediately. Instead, use environment variables or a secure configuration file that is not tracked in version control (add to .gitignore).
Here's what I looked at during the review
- 🟢 General issues: all looks good
- 🔴 Security: 1 blocking issue
- 🟢 Testing: all looks good
- 🟢 Complexity: all looks good
- 🟢 Documentation: all looks good
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
@@ -1,4 +1,4 @@ | |||
from aiogram import Bot | |||
|
|||
bot_token = '' | |||
bot_token = '7792865144:AAGBlt5yzwo43zhD7s7UIVjN4TAJFGVY7M8' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🚨 issue (security): Do not commit bot tokens or other credentials directly in source code
This token should be moved to environment variables or a secure configuration management system. Please invalidate this token immediately as it has been exposed in version control.
Summary by Sourcery
Chores:
cfg.py
.