I did a search and surprisingly found no answer. Right now we don't commit our API Keys/.env file on a repo that a growing team of 4 is working on. Whenever we change something, like say, a DB Password, we send it out to each other via Slack.
This seems pointless considering our repo is Private, not forkable, and is only given access to by employees.
The only ways I could see this going wrong are:
- Employee accidentally published the repo publicly. Though this would be a disaster anyway since our whole codebase would be public, so I fail to see how changing keys and passwords would be our biggest concern.
- An employee account is compromised. See above ^ (We also enforce MFA as a consolation).
- GitHub themselves are breached, which again, we have bigger problems (and most software companies).
- Insert vague Microsoft conspiracy here
Is there a reason we should continue this practice or can we just commit our .env file?