Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Move the Healthchecks API key out of source code

Open
#6 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
42/100
Issue type
Refactor
Clarity
Mostly clear
Activity status
Quiet
Tech stack
go
Domain
ci-cd, cli, security

Research direction

Start by reading internal/status/status.go to trace how the Healthchecks API key is used when fetching cluster status. Define the credential source and missing-credential behavior, then verify that no key remains in source, the committed key is rotated, and CI includes lightweight secret scanning.

Written by the indexing model from the issue text.

Description

Problem

internal/status/status.go sets the Healthchecks API key directly in code when fetching cluster status.

For a public CLI repo, embedding service credentials in source makes key rotation harder and exposes access to anyone with the repository. Even if the current key is read-only or intentionally scoped, it should be treated as leaked once committed.

Suggested fix

  • Revoke/rotate the committed Healthchecks API key.
  • Load the key from an environment variable, config file, or backend endpoint instead of hardcoding it in the CLI.
  • Make the CLI fail with a clear message when status data requires credentials that are not configured.
  • Add a lightweight secret scanning check in CI.

Relevant file

  • internal/status/status.go
Dominant language
Go
Stars
0
Forks
1
Avg merge
1d 2h
Merged PRs (30d)
4

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from WATonomous/watcloud-cli

All issues in WATonomous/watcloud-cli

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.