Prevent bundling of .env and document secure handling of API keys#4
Prevent bundling of .env and document secure handling of API keys#4Ishaan400 wants to merge 1 commit intoAOSSIE-Org:mainfrom
Conversation
📝 WalkthroughWalkthroughDocumentation and configuration updates to improve security practices by preventing environment files from being committed to version control and bundled with application assets. Introduces guidance on using environment variables and CI/CD systems for secrets management. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
Pre-merge checks and finishing touches✅ Passed checks (3 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: defaults Review profile: CHILL Plan: Pro 📒 Files selected for processing (2)
🔇 Additional comments (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This PR removes
.envfrom being bundled into the app (by removing it from flutter.assets in pubspec.yaml), confirms that.envis listed in .gitignore, and adds a note to the README warning contributors not to commit API keys..env(confirmed)This helps reduce the risk of leaking secrets and improves onboarding for new contributors.
Summary by CodeRabbit
Documentation
.env.exampleusage and preventing.envcommits through.gitignore.Chores
✏️ Tip: You can customize this high-level summary in your review settings.