4 ms·
Yes, I definitely didn't think about this issue. Secret detection seems hard. Maybe "gut save" should inform the user which file will be committed to prevent
by julien040 4y ago
Yes, I definitely didn't think about this issue.
Secret detection seems hard.
Maybe "gut save" should inform the user which file will be committed to prevent committing a credentials file, but it's probably not the right solution.
I must look into that.
- danenania 4y agoIf anyone needs help keeping secrets out of git, you could give EnvKey[1] a look (disclaimer: I'm the founder). It aims to keep all secrets out of the repo completely so that you can't be burned by forgetting to add something to .gitignore or other mistakes along those lines. It takes a few minutes to install and then all your secrets and config will be in the environment, and will stay automatically up-to-date when there are changes. Might be a way to cut out that particular failure mode when using Gut (which looks interesting btw--kinda like Git: the good parts). 1 - https://github.com/envkey/envkey https://github.com/envkey/envkey
- 8organicbits 4y agoThere's some open source tools that attempt to help, but yeah, it's a hard problem. https://github.com/topics/secrets-detection https://github.com/topics/secrets-detection