This is too funny not to share.
Back in 2018, just before the
@OSHCutInc instant quoting app went live, I accidentally pushed our API keys to our private Github repo.
I must have fixed it shortly thereafter, but the keys remained in our Git history.
Anyway, our much more experienced software team just ran some security scans and it found the keys, with this commit message showing where the breach originated.
"Switched to LIVE API KEYS!!!"
lol
Glad to have actual professionals running the team now. :-)