@secretlint/secretlint-rule-no-dotenv
TypeScript icon, indicating that this package has built-in type declarations

8.2.4 • Public • Published

@secretlint/secretlint-rule-no-dotenv

A secretlint rule for dotenv.

Prevents commits .env file because it may contain credentials.

Install

Install with npm:

npm install @secretlint/secretlint-rule-no-dotenv

Usage

Via .secretlintrc.json(Recommended)

{
    "rules": [
        {
            "id": "@secretlint/secretlint-rule-no-dotenv"
        }
    ]
}

MessageIDs

FOUND_DOTENV_FILE

found .env file

Disallow to use .env file, because dotenv document describe that

Should I commit my .env file?

No. We strongly recommend against committing your .env file to version control.

-- https://github.com/motdotla/dotenv#should-i-commit-my-env-file

You can tell Secretlint to ignore .env file by .secretlintignore configuration.

For more details .secretlintignore, see following document.

Author

License

MIT © secretlint

Dependencies (1)

Dev Dependencies (6)

Package Sidebar

Install

npm i @secretlint/secretlint-rule-no-dotenv

Weekly Downloads

1,607

Version

8.2.4

License

MIT

Unpacked Size

8.46 kB

Total Files

8

Last publish

Collaborators

  • secretlint-bot
  • azu