Gitignore在GitHub代码中是否可以看到除我以外的任何人都可以看到的d` .env`文件吗?
背景
github允许您存储加密的秘密设置>代码> codespaces Secrets )对于安全性,存储的秘密一旦存储就永远不会看到它们。
但是,在黑客攻击新事物时,我发现能够偶尔看到我的秘密和其他环境变量很有用。通常,当在本地项目上黑客攻击时,我将将我的秘密存储在.env
文件中,该文件通过在我的.gitignore
文件中列出来将其拒之门。
我想对github codespaces做同样的问题
:将gitignore'd .env
文件存储在我的codespace中,仅对我可见。
但是,随着github代码生活在云中,尚不清楚此.env
文件是否会以某种方式可见。
问题
如果我 gitignore a .env
(或我的github codespase中的任何其他文件)是否会通过代码台面向其他文件可见吗?
Background
GitHub allows you to store Encrypted Secrets (Settings > Codespaces > Codespaces secrets), which is an amazing feature. For security, secrets stored this way are never visible to you once they are stored.
However, while hacking on something new, I find that it’s useful to be able to see my secrets and other environment variables occasionally. Typically, when hacking on a local project, I’ll store my secrets in a .env
file, which is kept out of source control by listing it in my .gitignore
file.
Issue
I’d like to do the same with GitHub Codespaces: store a gitignore’d .env
file in my Codespace that is visible only to me.
However, with GitHub Codespaces living in the cloud, it is unclear whether this .env
file would be somehow visible to others.
Question
If I gitignore a .env
(or any other) file in my GitHub Codespace, is that file going to be somehow visible via the Codespace to others?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
我收到
这是我想要的答案。
除了有用的情况下,他还指出了线程:
I received this answer on Twitter from GitHub employee Jonathan Carter (@LostInTangent) yesterday:
This is the answer I was looking for.
As a helpful aside, he additionally notes in-thread: