- β Use environment variables for ALL credentials
- β
Copy
.env.exampleto.envand add your credentials there - β
Keep
.envin.gitignore(already configured) - β
Use
process.env.VARIABLE_NAMEin your code - β
Review your commits before pushing (
git diff) - β Use placeholders when asking AI assistants for help
- β Never hardcode API keys in your code
- β Never commit
.envfiles - β Never share credentials in code comments
- β Never commit files with "credential", "secret", or "password" in the name
- β Never remove patterns from
.gitignoreor.bobignore - β Never paste credentials in AI assistant prompts
AI assistants log your prompts and code in session history files. If you share credentials with them, those credentials may be logged!
β BAD: "Here's my API key: abc123xyz, help me use it"
β
GOOD: "Help me use environment variables for my API key"
β BAD: "Read my .env file and help me debug"
β
GOOD: "Help me structure my .env file (I'll add credentials myself)"
β BAD: api_key = "abc123xyz"
β
GOOD: api_key = os.getenv('API_KEY')
.bobignoreprevents Bob from logging credential patterns.gitignoreprevents session files from being committed- But YOU must not share credentials in prompts!
If you accidentally commit credentials:
- Your IBM Cloud account will be suspended immediately
- You must remove the credential from repository history
- You must rotate/revoke the exposed credential
- Your account will be restored after verification
require("dotenv").config();
const apiKey = process.env.IBM_CLOUD_API_KEY;import os
from dotenv import load_dotenv
load_dotenv()
api_key = os.getenv('IBM_CLOUD_API_KEY')String apiKey = System.getenv("IBM_CLOUD_API_KEY");- No hardcoded credentials in code
-
.envfile is NOT staged for commit - No files with credentials in their name
- Reviewed
git difffor sensitive data - All credentials are in environment variables
- No credentials shared with AI assistants
Contact hackathon support through the mentor channel.