BlockBeats news, on May 20, CZ posted that if an API key exists in the code, even in a private repository, it should be immediately checked and replaced to prevent potential security risks. This alert follows an official notice from GitHub this morning. GitHub stated that it is investigating an unauthorized access incident involving its internal codebase. GitHub noted that there is currently no evidence that data stored by customers outside the GitHub platform—including enterprise, organizational, or code repositories—has been affected, but the company is continuously monitoring its infrastructure for any further anomalous activity.
GitHub states that if it is later confirmed that user data or services have been affected, customers will be notified through existing incident response and communication channels.


