protect
Install a required Git clean filter for all existing and future repositories for your user. Run this once, even outside a Git repository:
Usage
Run once to protect existing and future repositories on this machine:
$ dotenvx protect
⛉ protection: full (.env*, .env.keys*)
That's it! Attempts to add unencrypted .env secrets to a commit by you (or your coding agent) will be blocked. It even works if your coding agent attempts git add -f.
Under the hood, this uses a Git filter to check env files before they're staged, letting encrypted files through unchanged. It's installed globally for your Git user, so it works across existing and future repositories on this machine.
FAQ
- Does it protect existing and future repositories?
- Does it work in monorepos and subdirectories?
- Does the plaintext check block git add -f too?
- Can I still commit encrypted env files?
- Can I check Docker builds with dotenvx protect --docker?
Related