Welcome Guest, Not a member yet? Register   Sign In
Working with Configuration Files
#9

(03-06-2024, 12:24 PM)kilishan Wrote: The problem with supporting multiple env files is that it encourages devs to save those in their git repositories, which is a horrible idea from a security standpoint. Since these files often include security credentials for various platforms, they should never be committed into a version control system because they're much easier for people to find and abuse. Instead, they should only be placed on the server they have the credentials for. That way someone would need access to the server's file system to get at your credentials. And if they've gotten that far you've likely got other issues, too.

Pushing .env files to git is considered dangerous, you're right, but pushing one or more of them makes little difference to me. I don't push any of them.
Reply


Messages In This Thread
Working with Configuration Files - by dave friend - 05-27-2018, 11:59 AM
RE: Working with Configuration Files - by b126 - 03-06-2024, 10:41 AM
RE: Working with Configuration Files - by b126 - 03-07-2024, 03:56 AM



Theme © iAndrew 2016 - Forum software by © MyBB