unkey_. The API keys you issue to your own users use prefixes you choose, so nobody gets emailed about them.
What happens
GitHub finds the key
GitHub spots a string that looks like an Unkey root key in a public repository and reports it to us with the URL where it was found.
We check it's a live root key
If the string matches a root key that exists and hasn’t been deleted, GitHub marks the alert as a real leak for the repository owner. Otherwise it’s marked as a false positive, and nobody is emailed.
What you should do
Treat the key as compromised. Anyone could have copied it, so replacing it is the only fix:- Under Settings > Root Keys, rotate the key with “revoke immediately”, or delete it.
- Update the service that used it.
- Remove the secret from the repository’s history.