Skip to content

Security: py-tr/earshot

Security

SECURITY.MD

Security Guidelines for Watsonx Hackathon

πŸ”’ Credential Management

βœ… DO:

  • βœ… Use environment variables for ALL credentials
  • βœ… Copy .env.example to .env and add your credentials there
  • βœ… Keep .env in .gitignore (already configured)
  • βœ… Use process.env.VARIABLE_NAME in your code
  • βœ… Review your commits before pushing (git diff)
  • βœ… Use placeholders when asking AI assistants for help

❌ DON'T:

  • ❌ Never hardcode API keys in your code
  • ❌ Never commit .env files
  • ❌ Never share credentials in code comments
  • ❌ Never commit files with "credential", "secret", or "password" in the name
  • ❌ Never remove patterns from .gitignore or .bobignore
  • ❌ Never paste credentials in AI assistant prompts

πŸ€– Using AI Assistants Safely (Bob, Copilot, etc.)

The Risk

AI assistants log your prompts and code in session history files. If you share credentials with them, those credentials may be logged!

Safe Practices:

❌ BAD:  "Here's my API key: abc123xyz, help me use it"
βœ… GOOD: "Help me use environment variables for my API key"

❌ BAD:  "Read my .env file and help me debug"
βœ… GOOD: "Help me structure my .env file (I'll add credentials myself)"

❌ BAD:  api_key = "abc123xyz"
βœ… GOOD: api_key = os.getenv('API_KEY')

Protection:

  • .bobignore prevents Bob from logging credential patterns
  • .gitignore prevents session files from being committed
  • But YOU must not share credentials in prompts!

🚨 What Happens if You Expose Credentials?

If you accidentally commit credentials:

  1. Your IBM Cloud account will be suspended immediately
  2. You must remove the credential from repository history
  3. You must rotate/revoke the exposed credential
  4. Your account will be restored after verification

πŸ“ How to Use Environment Variables

Node.js / JavaScript

require("dotenv").config();
const apiKey = process.env.IBM_CLOUD_API_KEY;

Python

import os
from dotenv import load_dotenv
load_dotenv()
api_key = os.getenv('IBM_CLOUD_API_KEY')

Java

String apiKey = System.getenv("IBM_CLOUD_API_KEY");

πŸ” Before You Commit Checklist

  • No hardcoded credentials in code
  • .env file is NOT staged for commit
  • No files with credentials in their name
  • Reviewed git diff for sensitive data
  • All credentials are in environment variables
  • No credentials shared with AI assistants

πŸ†˜ Need Help?

Contact hackathon support through the mentor channel.

πŸ“š Additional Resources

There aren't any published security advisories