Compare commits

...

6 Commits

Author SHA1 Message Date
Russell Shean
73704d67df
Merge a614252a10 into c677dd99d4 2026-04-08 16:43:48 +05:00
Devin Dooley
c677dd99d4
Merge pull request #4834 from wispgitgecko9/patch-2
Update macOS.gitignore
2026-04-07 20:04:22 -07:00
Devin Dooley
a78658650d
Revert change to Icon rule 2026-04-07 20:02:07 -07:00
WiSP
6a7b122e75
Update macOS.gitignore
Added .localized file to the gitignore.
2026-04-03 21:59:36 -05:00
Russell Shean
a614252a10
Merge pull request #1 from Russell-Shean/Russell-Shean-patch-1
R: add `.env` to prevent accidentally exposing credentials
2025-12-19 19:30:56 +08:00
Russell Shean
460b9d97a7
R: add .env to prevent accidentally exposing credentials
Historically R users have used the .Renviron file for storing environmental variables such as secrets, credentials, API keys etc. However, I believe there are several compelling reasons for adding .env to the .gitignore too:

1. The dotenv R package was created to allow users to use .env instead of .Renviron. The package has a significant number of downloads.  https://github.com/gaborcsardi/dotenv 

2. .env files are standard in many other programming languages. It wouldn't be that out of the unexpected to think R users might end up with an .env file because a python user on their team contributed files to the repo, the R user started programming in nodejs and is used to working with .env file, or a repo is in the process of being translated from a language that uses .env to R. 

3. LLMs are making programming accessible to people who may not have much previous experience handling credentials and security. One of the first steps many of these users have to do is store LLM provider API keys somewhere. I worry about a new R user adapting a python workflow or an R workflow that recommends using an .env file and then accidentally committing their LLM API keys to a public repo. 

4. I can't think of why an R user would create an .env file for any other reason other than storing credentials and environmental variables. If, for whatever reason, they need to commit an .env file, they can remove that part from the template, but I think the risk of accidentally exposing sensitive credentials justifies adding .env files to the template and not commenting it out by default.
2025-12-19 19:27:15 +08:00
2 changed files with 2 additions and 0 deletions

View File

@ -1,5 +1,6 @@
# General # General
.DS_Store .DS_Store
.localized
__MACOSX/ __MACOSX/
.AppleDouble .AppleDouble
.LSOverride .LSOverride

View File

@ -38,6 +38,7 @@ vignettes/*.pdf
# R Environment Variables # R Environment Variables
.Renviron .Renviron
.env
# pkgdown site # pkgdown site
docs/ docs/