6 ms·
> Alternatively, don't commit passwords/API-keys/sensitive-info to your repo. This is, of course, the right answer. However, it's frustrating that several fra
by lambda 12y ago
> Alternatively, don't commit passwords/API-keys/sensitive-info to your repo.
This is, of course, the right answer.
However, it's frustrating that several frameworks make this very easy to get wrong. Anything that has an application.yml, database.yml, or similar configuration file that normally lives within the same directory as the source code, and which is intended to contain credentials, means that lots of people will make that mistake.
It's one of the fundamental errors that you see so often in web frameworks like Rails, this whole idea of mixing application code and configuration files into one big tree. I don't know how this practice caught on, but it has, and it so frequently causes mistakes, both big ones like accidentally publishing credentials, and simply frustrating ones like confusing the difference between application code and configuration in ways that make it more difficult to have multiple local configurations and updating the application code independently.
- deleted 12y ago[deleted]