The classics, before every publish:
- "oops I committed .env" — your API key is now in git history forever, and revoking it is the easy part; explaining it in the incident channel is not.
- "oops, no license" — you wrote a great README, got 200 stars, and your code legally belongs to no one.
-
"oops, it's 400MB" — three people committed their datasets to
data/andgit clonenow takes longer than onboarding. -
"oops, vendor lock-in" — a three-file "zero-dependency" utility that quietly
import requests,import click, andimport dotenv.
repo-health is the 60-second gate that catches these before your repo goes public, not after:
git clone https://github.com/hahahahahahahahah6/repo-health
cd repo-health
python3 repo_health.py .
repo-health 0.1.0 — /home/hao/projects/agent-guard
[✓ PASS] license LICENSE
[✓ PASS] readme README.md
[! WARN] gitignore no .gitignore found
[✗ FAIL] secrets 1 suspicious file(s): .env
[! WARN] fat-files 1 file(s) over 1MB: assets/demo.mp4 (12.4MB)
[✓ PASS] todos 7 TODO/FIXME/XXX/HACK markers
[! WARN] stdlib-only third-party imports: requests
summary: 3 pass / 3 warn / 1 fail
Seven checks: license and readme (missing either is a FAIL), gitignore, secrets (flags .env, *.pem, *.key, id_rsa*, *secret* by filename — contents are never printed), fat-files (anything over 1MB), todos (a pile-up of TODO/FIXME/XXX/HACK), and stdlib-only (names any import outside the standard library, so a stray import requests can't hide behind a "zero-dependency" README). Exit 0 when clean, 1 on any FAIL; --json for CI.
Note: it's not on PyPI — the repo-health name there belongs to an unrelated project. Run it straight from source; it's one file, zero dependencies.
And it's not a security scanner — gitleaks and trufflehog do entropy analysis and history scanning. This is the hygiene gate: the last command before git push to a public repo, or the first command in CI on a new project.
19/19 tests pass. MIT licensed.
Repo: https://github.com/hahahahahahahahah6/repo-health
What's your worst "oops" moment right after making a repo public?
Top comments (0)