-
-
Notifications
You must be signed in to change notification settings - Fork 7.5k
Closed
Description
After running the installation instructions, there appears to be two files containing secrets. Neither of which is in the gitignore and one of which is already versioned:
.env
.copier/.copier-answers.yml.jinja
Both of these files contain sensitive data that should not appear in version control histories (including tokens and passwords). These files should not be versioned for security reasons, in addition, .env contents will vary across development machines (eg, passwords for staging systems).
I suggest splitting the data into two files, one which is safe to version and one which is not.
Metadata
Metadata
Assignees
Labels
No labels