You stage everything with one click, type "fix login redirect", commit, push. The next morning the pull request has 4,812 changed files. Or six, and one of them is .env. Or CI is green because you left it.only( in a spec and the other 400 tests never ran.
None of this is hard. It is just that nothing looked at the git index before the commit happened.
The usual suspects
| Staged by accident | Why it hurts |
|---|---|
.env, *.pem, id_rsa, credentials.json
|
A pushed secret is a leaked secret: rotate it |
Tokens in .npmrc / .pypirc, *.tfstate
|
Publish tokens and plain-text infra secrets |
dump.sql, big binaries |
Every clone carries them forever |
node_modules/, dist/, .DS_Store
|
Thousands of files of review noise |
<<<<<<< markers, debugger;
|
Broken or frozen code |
it.only(, fdescribe(
|
The file reports PASS, the rest never runs |
This is not only a side-project problem: Toyota disclosed in 2022 that a data-server access key had sat in a public GitHub repo for almost five years (BleepingComputer).
Why hooks are not enough on their own
.gitignore only helps if the pattern exists before you stage, and it cannot see content. Pre-commit hooks are the right gate for teams, but they live in each clone and need setup in every repository. Most repositories you touch in a week do not have one.
Already committed it?
git restore --staged .env # still only staged
git rm --cached .env && echo ".env" >> .gitignore
git commit --amend --no-edit # committed, not pushed
If it was pushed: rotate the secret first, then clean history with git filter-repo.
Catch it while it is staged
I built CommitSieve, a free VS Code extension that checks the staged changes of every repository in your workspace, live, with zero setup. The status bar shows CommitSieve: 3 issues the moment you stage something, each finding has Unstage and Add to .gitignore buttons, and content findings land in the Problems panel.
It only looks at lines your staged diff adds, leaves directories that already exist in HEAD alone, and knows that model.fit( is not a focused test. No network, no telemetry, hardened git calls. It warns rather than blocks (VS Code has no commit hook API), so keep a hook or CI scanner as the hard gate.
code --install-extension jaytankdev.commitsieve
Source (MIT): github.com/jay-tank/commitsieve
Full write-up (all 13 rules, cleanup for every case, limitations, FAQ): Stop committing .env files, node_modules and it.only
Top comments (0)