fix: complete SENSITIVE_ENV_KEYS to cover all runtime API keys#171
Conversation
Add MINIMAX_API_KEY, XIAOMI_API_KEY, USE_GITHUB_TOKEN to SENSITIVE_ENV_KEYS so that extra-env overrides of these keys trigger the existing ::warning::.
|
无遗漏 PR 描述明确指出需要将 经核查当前文件
且 |
|
可合并 本 PR 将 阻塞项:无 建议项(按共识程度排序):
📋 各 Reviewer 详细审查结果quality可合并 本 PR 在 阻塞项:无 建议项:
security安全无虞 此 PR 在 阻塞项:无 建议项:
performance性能良好 阻塞项:无 architecture架构有疑虑 本次 PR 仅修改 架构层面的分析:
阻塞项:无 建议项:
|

From PR #170 review suggestions.
SENSITIVE_ENV_KEYSwas missingMINIMAX_API_KEY,XIAOMI_API_KEY, andUSE_GITHUB_TOKEN— all set byrun-github-opencode.pyat runtime. This meantextra-envoverrides of these keys would silently succeed without the::warning::that other sensitive keys trigger.