GitHub flagged a Google API key in my repository. It was a fixture I had made up — sequential filler after the AIza prefix, never a real credential.

What I didn't expect was the sidebar on the alert page. Under Public leaks, GitHub lists every other public repository where it has seen the same string:

…/chat/tests/test_pii_detector.py

…/scanner/core/scanCode.test.ts

…/extensions/secret-guard/redact.test.js