Skip to content

What not to commit

Last updated:

An API key or password ended up in a commit.

Terminal window
git rm --cached .env

If .env was already pushed, rotate the key first, then stop tracking the file. Rewriting history to remove it is optional and never enough on its own: every existing clone still has a copy.

.env
Terminal window
git add .gitignore
git commit -m "Stop tracking .env"
node_modules/
dist/
*.log
Terminal window
git add .gitignore
git commit -m "Ignore build output"

Start from your framework’s .gitignore template and keep it short: only the paths your build produces.

Terminal window
git config --global core.excludesFile ~/.gitignore_global
.DS_Store
Thumbs.db
.idea/
.vscode/

This file lives outside the repository and applies to every repository on your machine, so it belongs to you, not to the project.

A binary file that changes often, such as a design file or a video, bloats a repository fast because Git keeps every version. See Large files with Git LFS for how to track it instead.

* text=auto

A file committed with Windows line endings (CRLF) shows as fully changed to a teammate on macOS or Linux, and the other way around. .gitattributes tells Git to normalize line endings on checkout and commit.

Terminal window
git add --renormalize .
git commit -m "Normalize line endings"

Git basics is licensed under CC BY 4.0: copy it, adapt it, keep the credit.