DEV Community

Discussion on: Please don't commit .env

Collapse
 
somedood profile image
Basti Ortiz

How did you guys manage the situation? Did everyone scramble to reset the API keys while others scrambled to clean up the working tree and commit history?

Collapse
 
itachiuchiha profile image
Itachi Uchiha

I regenerate the mail and bank API keys. I also bank added IP limit to bank API portal.

Our lead was so angry. I created a script to remove critical commit histories before we faced this situation (about 2 years ago). I ran that shell script.

But it was so dangerous. Normally we don't have published repositories.

I can say this was our fault.

Thread Thread
 
somedood profile image
Basti Ortiz

I take it that the intern didn't stay there for long...