Is it acceptable to commit API Keys and .env files to a private business repo?

Viewed 2255

I did a search and surprisingly found no answer. Right now we don't commit our API Keys/.env file on a repo that a growing team of 4 is working on. Whenever we change something, like say, a DB Password, we send it out to each other via Slack.

This seems pointless considering our repo is Private, not forkable, and is only given access to by employees.

The only ways I could see this going wrong are:

  1. Employee accidentally published the repo publicly. Though this would be a disaster anyway since our whole codebase would be public, so I fail to see how changing keys and passwords would be our biggest concern.
  2. An employee account is compromised. See above ^ (We also enforce MFA as a consolation).
  3. GitHub themselves are breached, which again, we have bigger problems (and most software companies).
  4. Insert vague Microsoft conspiracy here

Is there a reason we should continue this practice or can we just commit our .env file?

1 Answers
Related