Ask HN: Keeping secrets out of public repos
How do you prevent API keys, passwords, private key files, etc.. from getting accidentally uploaded to Github/Gitlab/Bitbucket? Is it OK to store them in private repos?
Also in my opinion, for your own dev work, source a file well outside of anywhere your code might live that has name=value pairs. Give the file name something highly obscene, long and upper-case that would be obvious if you contemplating committing it.
See if your git repo has a policy against a certain file name and use that. People will do what people can do and mistakes happen. :-)
The easy method is to use something like dotenv or a separate config file under gitignore.
We use knox [1], but there are other popular ones.
Edit: typos
If you never put credentials in your code, then even during panic mode you won't do it.