After checking the contents of the file to send the report, I was surprised.
Surprisingly, clearly sensitive information such as GITHUB_REPO_API_KEY and WORKERS_KV_API_TOKEN was displayed. I couldn’t understand what happened for a moment, and when I checked the command log, I found that I accidentally put a link to /proc/self/environ instead of /proc/self/maps.
[…]
It seems that GitHub notified Cloudflare immediately because GITHUB_REPO_API_KEY (API key of GitHub) was included in the repository, and Cloudflare started incident response immediately after the notification.
[…]
April 6, 2021 20:30 cdnjs processed the file
At the same time GitHub sent an alert to Cloudflare
At the same time Cloudflare started an incident response
Within minutes Cloudflare finished revocation of credentials
April 6, 2021 20:40 I sent an initial report
This a nice Github feature. Also kudos to Cloudflare for quickly reacting to this.