Repository navigation
fix(security): remove leaked Gitalk secret, bump CI actions, migrate to Giscus - #34
Merged
Merged
Conversation
- Remove Gitalk OAuth config (client_secret was previously committed; rotate in GitHub Developer settings) - Switch comments provider from Gitalk to Giscus with Butterfly-compatible settings - Add _config.butterfly.local.yml to .gitignore for untracked local overrides - Document that pages.yml uses actions/checkout@v4 and actions/setup-node@v4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR addresses three items: remove a previously committed Gitalk OAuth secret, confirm GitHub Actions are on v4, and migrate the comment system from Gitalk to Giscus.
1) P0 Security — Gitalk
client_secretremovedgitalkblock from_config.butterfly.yml(theclient_secretandclient_idwere committed in git history as early as 2023)._config.butterfly.local.ymlto.gitignorefor untracked local overrides.2) CI — GitHub Actions v4
The repository does not have
.github/deploy.yml; deployment is handled by.github/workflows/pages.yml(added inc288f23).That workflow already uses:
actions/checkoutactions/setup-nodecache: npm)actions/configure-pagesactions/upload-pages-artifactactions/deploy-pagesNo
actions/cache@v2references remain in the repo.setup-node@v4handles npm caching natively, so a separateactions/cachestep is unnecessary. A brief comment was added topages.ymldocumenting this.3) Gitalk → Giscus migration
Comments are switched to Giscus in Butterfly theme config:
comments.use: Giscusgiscus.repo: Shirolin/Shirolin.github.iodata-lang,data-mapping,data-strict,data-input-position,data-category)light_theme/dark_theme(replacing the incorrect nestedtheme:block)repo_idandcategory_idare left as placeholders — they must be filled in after completing the manual Giscus setup below. Comments will not appear on the live site until those IDs are set.Manual follow-up checklist
Complete these steps to activate Giscus comments:
Shirolin/Shirolin.github.io(Repo → Settings → General → Features → Discussions)Shirolin.github.ioGeneral— must matchgiscus.option.data-categoryin config)Shirolin/Shirolin.github.io, choose the category, and copy the generated Repository ID and Category IDrepo_idandcategory_idinto_config.butterfly.ymlunder thegiscus:sectionnpm run buildor push tomasterto trigger CI)Testing
npm run buildpasses locally (format, lint, tsc, hexo generate).