Yesterday, CircleCI posted a security alert to its users and on its blog:
Matplotlib uses CircleCI to build its documentation on Pull Requests to enable easier review. We also use its builds to update documentation available at Welcome to Matplotlib Sphinx Theme’s documentation! — Matplotlib Sphinx Theme documentation and Matplotlib documentation — Matplotlib 3.7.0.dev1231+gcbaeadb090 documentation. Some secrets were made available to CircleCI in order to allow this deployment.
In accordance with the recommendations from CircleCI, we have replaced all (read-write and read-only) security keys used for CircleCI on all projects in the Matplotlib organization.