Tagged: security
6 posts · all posts
- Lovable environment variables: what's secret
15 September 2026
Not every value in your Lovable env is a secret, and some things you think are safe aren't. Here's how to tell which is which before you ship.
- My Lovable app got hacked: what to do in the first hour
4 September 2026
A calm, ordered playbook for the first 60 minutes after your Lovable app is compromised: contain, rotate, assess, and recover without making it worse.
- Supabase service_role key exposed: how to check and fix it
8 August 2026
A precise, Supabase-specific check for a leaked service_role key in your frontend bundle, plus the exact rotation steps in the Supabase dashboard.
- How Claude Code projects leak API keys
7 August 2026
AI-generated projects often hardcode secrets or commit .env files by accident. Here's how to scan your Claude Code project for leaked keys in a few minutes.
- Check for exposed API keys in 5 minutes
7 July 2026
A copy-pasteable, 5-minute self-check for whether your Lovable or backend-as-a-service app is leaking a privileged key to anyone who opens the page.
- The production checklist for Lovable apps
7 July 2026
A 15-point checklist for Lovable, Bolt, and Claude Code apps: real commands to check leaked keys, missing backups, open admin routes.