Gemini API Key
ID |
gemini_key |
Severity |
high |
Vendor |
|
Family |
API Token |
Description
Gemini (Bard) provides APIs for accessing various AI models for tasks such as text generation, language translation, and more.
Security
Any hardcoded Gemini Key is a potential secret reported by this detector.
Accidentally checking-in the key to source control repositories could compromise your Gemini account.
Mitigation / Fix
-
Remove the API Key from the source code or committed configuration file.
-
Follow your policy for handling leaked secrets, which typically require revoking the secret in the target system(s). Go to your settings page in the Gemini dashboard to revoke the key.
-
If under a git repository, you may remove unwanted files from the repository history using tools like git filter-repo or BFG Repo-Cleaner. You may follow the procedure listed here for GitHub.
You should consider any sensitive data in commits with secrets as compromised. |
Remember that secrets may be removed from history in your projects, but not in other users' cloned or forked repositories.