GitHub Secret Scanning Now Detects Lovable Labs, Supabase, and Pydantic Services Inc. Secrets
GitHub has expanded its secret scanning coverage to include new API key and token types from Lovable Labs, Supabase, and Pydantic Services Inc., with automatic partner notification for exposed public secrets.
What changed?
GitHub Secret Scanning now detects new secret types from Lovable Labs, Supabase, and Pydantic Services Inc. This includes lovable_api_key, supabase_oauth_access_token, supabase_scoped_personal_access_token, logfire_token, and pydantic_ai_gateway_api_key. When GitHub finds a supported partner secret in a public repository, it automatically notifies the provider so they can revoke or rotate the credential. User secrets found in both public and private repositories generate secret scanning alerts.

Why does it matter to an everyday developer?
This change reduces the risk of credential leaks for developers using Lovable Labs, Supabase, and Pydantic Services Inc. APIs. Automatic detection and provider notification help prevent misuse of exposed secrets. Developers benefit from a net reduction in incident response time and can more confidently use GitHub for collaborative development, knowing secrets are being proactively monitored.
What can the developer do now?
Developers should ensure that GitHub Secret Scanning is enabled in their repositories, especially those integrating with Lovable Labs, Supabase, or Pydantic Services Inc. If a relevant secret is detected, GitHub will generate an alert and, in the case of public repositories, notify the provider automatically. Developers should rotate exposed secrets immediately and follow best practices for secret management, such as using environment variables and restricting repository permissions.
