DEV Community

Cover image for Stop committing .env files, node_modules and it.only: check your staged changes before you press Commit
TANK JAY
TANK JAY

Posted on Originally published at jaytank.hashnode.dev

Stop committing .env files, node_modules and it.only: check your staged changes before you press Commit

You stage everything with one click, type "fix login redirect", commit, push. The next morning the pull request has 4,812 changed files. Or six, and one of them is .env. Or CI is green because you left it.only( in a spec and the other 400 tests never ran.

None of this is hard. It is just that nothing looked at the git index before the commit happened.

The usual suspects

Staged by accident Why it hurts
.env, *.pem, id_rsa, credentials.json A pushed secret is a leaked secret: rotate it
Tokens in .npmrc / .pypirc, *.tfstate Publish tokens and plain-text infra secrets
dump.sql, big binaries Every clone carries them forever
node_modules/, dist/, .DS_Store Thousands of files of review noise
<<<<<<< markers, debugger; Broken or frozen code
it.only(, fdescribe( The file reports PASS, the rest never runs

This is not only a side-project problem: Toyota disclosed in 2022 that a data-server access key had sat in a public GitHub repo for almost five years (BleepingComputer).

Why hooks are not enough on their own

.gitignore only helps if the pattern exists before you stage, and it cannot see content. Pre-commit hooks are the right gate for teams, but they live in each clone and need setup in every repository. Most repositories you touch in a week do not have one.

Already committed it?

git restore --staged .env          # still only staged
git rm --cached .env && echo ".env" >> .gitignore
git commit --amend --no-edit       # committed, not pushed
Enter fullscreen mode Exit fullscreen mode

If it was pushed: rotate the secret first, then clean history with git filter-repo.

Catch it while it is staged

I built CommitSieve, a free VS Code extension that checks the staged changes of every repository in your workspace, live, with zero setup. The status bar shows CommitSieve: 3 issues the moment you stage something, each finding has Unstage and Add to .gitignore buttons, and content findings land in the Problems panel.

It only looks at lines your staged diff adds, leaves directories that already exist in HEAD alone, and knows that model.fit( is not a focused test. No network, no telemetry, hardened git calls. It warns rather than blocks (VS Code has no commit hook API), so keep a hook or CI scanner as the hard gate.

code --install-extension jaytankdev.commitsieve
Enter fullscreen mode Exit fullscreen mode

Source (MIT): github.com/jay-tank/commitsieve

Full write-up (all 13 rules, cleanup for every case, limitations, FAQ): Stop committing .env files, node_modules and it.only

Top comments (0)