logoalt Hacker News

s_devtoday at 3:44 PM2 repliesview on HN

The fact that it's hidden means it doesn't get commited by accident in most git repos unless explicitly added or configured that way.


Replies

deathanatostoday at 5:18 PM

No, it won't.

  ~/code
  » cd foo
  ~/code/foo
  » git init
  ± foo:main:/
  » touch .env
  ± foo:main:/
  » git add .
  ± foo:main:/
  » g s
  On branch main
  
  No commits yet
  
  Changes to be committed:
    (use "git rm --cached <file>..." to unstage)
   new file:   .env
  
  ± foo:main:/
  » 
File is added, kaboom. "It should be in .gitignore" yes, true, but that has nothing to do with it not getting committed because it is hidden.

And even with it in .gitignore, I've dealt with multiple security incidents where someone has managed to commit it anyways. (And yes, I'm aware there are commands to do this, but what I haven't figured out is why someone would work around the safety and not think "what's the point of this?" prior to the bullet ending up in the foot.)

fhntoday at 3:52 PM

there shouldn't be any secrets in it so committing it shouldn't be a huge problem.

show 1 reply