DEV Community

Discussion on: I tried to find MongoDB connection strings over 1000 public GitHub repositories

Collapse
 
rehman000 profile image
Rehman Arshad

This happened a fair amount of times to me to the point that whenever I start on any project where I plan on using any API keys I instinctively add .env to the .gitignore file immediately before anything else.

And I recall my professor telling me about actual bots sifting through github looking for api keys accidentally commited in git histories to exploit.

Some comments have been hidden by the post's author - find out more