Stop committing .env files, node_modules and it.only: check your staged changes before you press Commit

작성자

카테고리:

← 피드로
DEV Community · TANK JAY · 2026-09-29 개발(SW)

You stage everything with one click, type “fix login redirect”, commit, push. The next morning the pull request has 4,812 changed files. Or six, and one of them is .env. Or CI is green because you left it.only( in a spec and the other 400 tests never ran.

None of this is hard. It is just that nothing looked at the git index before the commit happened.

The usual suspects

Staged by accident Why it hurts .env, *.pem, id_rsa, credentials.json A pushed secret is a leaked secret: rotate it Tokens in .npmrc / .pypirc, *.tfstate Publish tokens and plain-text infra secrets dump.sql, big binaries Every clone carries them forever node_modules/, dist/, .DS_Store Thousands of files of review noise <<<<<<< markers, debugger; Broken or frozen code it.only(, fdescribe( The file reports PASS, the rest never runs

This is not only a side-project problem: Toyota disclosed in 2022 that a data-server access key had sat in a public GitHub repo for almost five years (BleepingComputer).

Why hooks are not enough on their own

.gitignore only helps if the pattern exists before you stage, and it cannot see content. Pre-commit hooks are the right gate for teams, but they live in each clone and need setup in every repository. Most repositories you touch in a week do not have one.

Already committed it?

git restore --staged .env          # still only staged
git rm --cached .env && echo ".env" >> .gitignore
git commit --amend --no-edit       # committed, not pushed

Enter fullscreen mode Exit fullscreen mode

If it was pushed: rotate the secret first, then clean history with git filter-repo.

Catch it while it is staged

I built CommitSieve, a free VS Code extension that checks the staged changes of every repository in your workspace, live, with zero setup. The status bar shows CommitSieve: 3 issues the moment you stage something, each finding has Unstage and Add to .gitignore buttons, and content findings land in the Problems panel.

It only looks at lines your staged diff adds, leaves directories that already exist in HEAD alone, and knows that model.fit( is not a focused test. No network, no telemetry, hardened git calls. It warns rather than blocks (VS Code has no commit hook API), so keep a hook or CI scanner as the hard gate.

code --install-extension jaytankdev.commitsieve

Enter fullscreen mode Exit fullscreen mode

Source (MIT): github.com/jay-tank/commitsieve

Full write-up (all 13 rules, cleanup for every case, limitations, FAQ): Stop committing .env files, node_modules and it.only

원문에서 계속 ↗