{
  "id": 10599485,
  "title": "Stop committing .env files, node_modules and it.only: check your staged changes before you press Commit",
  "url": "https://urgent.news/2026/09/29/stop-committing-env-files-node-modules-and-it-only-check-your-staged",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T03:31:14.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jaytank/stop-committing-env-files-nodemodules-and-itonly-check-your-staged-changes-before-you-press-5bf5"
  },
  "original_language": "en",
  "account": "Staging everything with a single click is convenient, but committing without checking can lead to headaches. A single \".env\" file added to the staged changes can turn a pull request into a nightmare, with 4,812 changes or even worse, a leaked secret. CI can be green only to find out later that only a few tests ran. Using it.only() in tests can cause the same issue, with the rest of the tests remaining untested. Secrets in .env, .pem, id_rsa, credentials.json, or in .npmrc, .pypirc, *.tfstate files are all at risk of being leaked. History repeats itself with node_modules/, dist/, .DS_Store, and large files that add noise to every clone. Pre-commit hooks are crucial for teams but require setup in every repository. Even then, they might not catch everything, like when content is already in the staged changes. Git ignore is not enough; it only helps if the pattern exists before staging. The best solution is to check the git index before committing, using tools like the CommitSieve extension in VS Code. This free extension checks staged changes in real-time, highlights issues, and even suggests adding files to .gitignore. It's a gentle warning, not a blocker, allowing developers to fix issues before committing. Remember, catching problems early is key, whether it's a .env file, a leaked secret, or untested tests.",
  "summary": "You stage everything with one click, type \"fix login redirect\", commit, push. The next morning the pull request has 4,812 changed files. Or six, and one of them is .env . Or CI is green because you left it.only( in a spec and the other 400 tests never ran. None of this is hard. It is just that nothing looked at the git index before the commit happened. The usual suspects Staged by accident Why it…",
  "key_points": [
    "Committing .env files can cause pull request nightmares with leaked secrets",
    "it.only() in tests can lead to untested code and green CI",
    "Pre-commit hooks and Git ignore are insufficient; use CommitSieve extension"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}