Skip to content

docs(api): scrubs a personal account from the application-key screenshots - #13077

Merged
mergify[bot] merged 1 commit into
mainfrom
devs/jd/jd/api-keys-screenshots-leak/scrubs-personal-account-app-key-screenshots--397ee771
Sep 29, 2026
Merged

mergify[bot] merged 1 commit into
mainfrom
devs/jd/jd/api-keys-screenshots-leak/scrubs-personal-account-app-key-screenshots--397ee771

Conversation

@jd

@jd jd commented Sep 29, 2026

Copy link
Copy Markdown
Member

Two of the screenshots on the API usage page were captured from a staff
member's own dashboard, so they published that person's full name, GitHub
login and profile photo.

  • application_keys.png: the name under the organization switcher now reads
    Jane Doe. The Mergifyio organization and the arrows pointing at the
    switcher and at Application Keys are unchanged.
  • application_keys_token.png: the sidebar header now shows an acme-corp
    organization with a letter avatar, the page text names acme-corp as the
    organization, and the Created By column shows janedoe with a generic
    avatar. The key names, scopes, dates and the Add Key button are
    unchanged.

Every identifier is painted over with the solid background colour and the
placeholder is drawn in Inter, matched to the original weight, size and
baseline, so nothing of the original survives under it. The third image,
application_keys_delete.png, needed no change: its background is blurred
past legibility at full resolution and the dialog names only the key.

This scrubs the images because the leak is already public. Recapturing them
from the sandbox organization will follow once dashboard capture works again.

Fixes Mergifyio/ci-bot#617

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

…hots

Two of the screenshots on the API usage page were captured from a staff
member's own dashboard, so they published that person's full name, GitHub
login and profile photo.

- `application_keys.png`: the name under the organization switcher now reads
  `Jane Doe`. The `Mergifyio` organization and the arrows pointing at the
  switcher and at **Application Keys** are unchanged.
- `application_keys_token.png`: the sidebar header now shows an `acme-corp`
  organization with a letter avatar, the page text names `acme-corp` as the
  organization, and the **Created By** column shows `janedoe` with a generic
  avatar. The key names, scopes, dates and the **Add Key** button are
  unchanged.

Every identifier is painted over with the solid background colour and the
placeholder is drawn in Inter, matched to the original weight, size and
baseline, so nothing of the original survives under it. The third image,
`application_keys_delete.png`, needed no change: its background is blurred
past legibility at full resolution and the dialog names only the key.

This scrubs the images because the leak is already public. Recapturing them
from the sandbox organization will follow once dashboard capture works again.

Fixes Mergifyio/ci-bot#617

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Change-Id: I397ee771f267691ad94cbea5d7e63b00a2d682a2
Copilot AI balanced review requested due to automatic review settings September 29, 2026 11:44
@mergify
mergify Bot deployed to Mergify Merge Protections September 29, 2026 11:44 Active

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mergify

mergify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Merge Protections

🟢 All 5 merge protections satisfied — ready to merge.

Show 5 satisfied protections

🟢 👀 Review Requirements

  • any of:
    • #approved-reviews-by >= 1
    • author = dependabot[bot]
    • author = renovate[bot]
    • all of:
      • author = mergify-ci-bot
      • -head ~= ^docs-agent/

🟢 Enforce conventional commit

Make sure that we follow https://www.conventionalcommits.org/en/v1.0.0/

  • title ~= ^(fix|feat|internal|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?!?:

🟢 🔎 Reviews

  • #changes-requested-reviews-by = 0
  • #review-requested = 0
  • #review-threads-unresolved = 0

🟢 📕 PR description

  • body ~= (?ms:.{48,})

🟢 🚦 Auto-queue

When all merge protections are satisfied, this pull request will be queued automatically.

@mergify
mergify Bot requested a review from a team September 29, 2026 11:46
@jd
jd marked this pull request as ready for review September 29, 2026 11:55
@mergify

mergify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

This pull request spent 3 minutes 5 seconds in the queue, including 2 minutes 43 seconds running CI.

Required conditions to merge

@mergify mergify Bot added the queued label Sep 29, 2026
@mergify mergify Bot mentioned this pull request Sep 29, 2026
36 of 49 tasks
@mergify
mergify Bot merged commit e1f0d12 into main Sep 29, 2026
13 checks passed
@mergify
mergify Bot deleted the devs/jd/jd/api-keys-screenshots-leak/scrubs-personal-account-app-key-screenshots--397ee771 branch September 29, 2026 13:04
@mergify mergify Bot removed the queued label Sep 29, 2026

This branch was successfully deployed

1 active deployment
Mergify Merge Protections — ff47e6c2 Deployed Sep 29, 2026 by mergify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants