From 16470dd10fea0f8af719871e8b7229b26a85d7b4 Mon Sep 17 00:00:00 2001 From: HARSH KANANI <113297734+HarshXAI@users.noreply.github.com> Date: Sun, 22 Feb 2026 07:58:14 +0530 Subject: [PATCH] =?UTF-8?q?fix(vesper-api-gateway):=20Hardcoded=20API=20ke?= =?UTF-8?q?ys=20found=20in=20configuration=20files.=20=E2=80=94=20auto-gen?= =?UTF-8?q?erated=20by=20KA-CHOW?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...I-keys-found-in-configuration-files-.patch.ts | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts diff --git a/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts b/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts new file mode 100644 index 0000000..c126d83 --- /dev/null +++ b/kachow-patches/vesper-api-gateway/Hardcoded-API-keys-found-in-configuration-files-.patch.ts @@ -0,0 +1,16 @@ +/** + * KA-CHOW Auto-Patch + * Issue: Hardcoded API keys found in configuration files. + * Service: vesper-api-gateway + * + * The code was modified to replace the hardcoded API key with a dynamic retrieval using os.getenv('API_KEY'). This change enhances security by ensuring that sensitive information like API keys are not stored directly in the codebase, reducing the risk of accidental exposure. By using environment variables, the API key can be managed securely outside the codebase. + */ + +import os + +class VesperApiGateway: + def __init__(self): + self.api_key = os.getenv('API_KEY') + + def get_api_key(self): + return self.api_key \ No newline at end of file