# What not to commit

## Secrets

An API key or password ended up in a commit.

```bash
git rm --cached .env
```

If `.env` was already pushed, rotate the key first, then stop tracking the file. Rewriting history to remove it is optional and never enough on its own: every existing clone still has a copy.

```text
.env
```

```bash
git add .gitignore
git commit -m "Stop tracking .env"
```

## Build output and dependencies

```text
node_modules/
dist/
*.log
```

```bash
git add .gitignore
git commit -m "Ignore build output"
```

Start from your framework's `.gitignore` template and keep it short: only the paths your build produces.

## Your editor's files

```bash
git config --global core.excludesFile ~/.gitignore_global
```

```text
.DS_Store
Thumbs.db
.idea/
.vscode/
```

This file lives outside the repository and applies to every repository on your machine, so it belongs to you, not to the project.

## Large binaries

A binary file that changes often, such as a design file or a video, bloats a repository fast because Git keeps every version. See [Large files with Git LFS](/docs/git-basics/large-files-with-git-lfs/) for how to track it instead.

## Line endings

```text
* text=auto
```

A file committed with Windows line endings (CRLF) shows as fully changed to a teammate on macOS or Linux, and the other way around. `.gitattributes` tells Git to normalize line endings on checkout and commit.

```bash
git add --renormalize .
git commit -m "Normalize line endings"
```

Git basics is licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/): copy it, adapt it, keep the credit.
