Keeping secrets out of a repository

Back to list2025-02-08
You

What is the practical way to stop credentials landing in commits?

ChatGPT

Two layers: a pre-commit hook that scans staged content, and push protection on the hosting side as a backstop. Neither is sufficient alone, because hooks are skipped with --no-verify and server-side scanning only sees what already left your machine.