DEV Community

hao li
hao li

Posted on Originally published at github.com

The 60-second gate I run before any repo goes public.

The classics, before every publish:

  • "oops I committed .env" — your API key is now in git history forever, and revoking it is the easy part; explaining it in the incident channel is not.
  • "oops, no license" — you wrote a great README, got 200 stars, and your code legally belongs to no one.
  • "oops, it's 400MB" — three people committed their datasets to data/ and git clone now takes longer than onboarding.
  • "oops, vendor lock-in" — a three-file "zero-dependency" utility that quietly import requests, import click, and import dotenv.

repo-health is the 60-second gate that catches these before your repo goes public, not after:

git clone https://github.com/hahahahahahahahah6/repo-health
cd repo-health
python3 repo_health.py .
Enter fullscreen mode Exit fullscreen mode
repo-health 0.1.0 — /home/hao/projects/agent-guard

[✓ PASS] license       LICENSE
[✓ PASS] readme        README.md
[! WARN] gitignore     no .gitignore found
[✗ FAIL] secrets       1 suspicious file(s): .env
[! WARN] fat-files     1 file(s) over 1MB: assets/demo.mp4 (12.4MB)
[✓ PASS] todos         7 TODO/FIXME/XXX/HACK markers
[! WARN] stdlib-only   third-party imports: requests

summary: 3 pass / 3 warn / 1 fail
Enter fullscreen mode Exit fullscreen mode

Seven checks: license and readme (missing either is a FAIL), gitignore, secrets (flags .env, *.pem, *.key, id_rsa*, *secret* by filename — contents are never printed), fat-files (anything over 1MB), todos (a pile-up of TODO/FIXME/XXX/HACK), and stdlib-only (names any import outside the standard library, so a stray import requests can't hide behind a "zero-dependency" README). Exit 0 when clean, 1 on any FAIL; --json for CI.

Note: it's not on PyPI — the repo-health name there belongs to an unrelated project. Run it straight from source; it's one file, zero dependencies.

And it's not a security scanner — gitleaks and trufflehog do entropy analysis and history scanning. This is the hygiene gate: the last command before git push to a public repo, or the first command in CI on a new project.

19/19 tests pass. MIT licensed.

Repo: https://github.com/hahahahahahahahah6/repo-health

What's your worst "oops" moment right after making a repo public?

Top comments (0)