Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -66,3 +66,14 @@ env/
.env
*.key
secrets*

# Any .env variant, however it was renamed. `.env` alone is not enough, and
# this has cost the family twice: craigslist-scraper's own .gitignore records
# a `.env.hold` made while testing that was committed WITH A LIVE KEY in it,
# recoverable only because that repo was private at the time. On 2026-09-17
# a sibling had an untracked `.env.bak` holding a 32-hex key in a PUBLIC
# repository, one `git add -A` from publication. Craigslist was fixed then
# and the fix never reached anyone else, which is §16's rule unapplied: when
Comment on lines +70 to +76

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This comment states very specific incidents as fact — a committed .env.hold with a live key in craigslist-scraper, and "a sibling" leaking a 32-hex key in a public repo — with no way to verify either from this repo, and no link/reference to where they're documented. Notably, the second incident is dated exactly to today (2026-09-17), the same day this PR was opened, which is worth double-checking rather than taking at face value. If these are real postmortems, consider linking to them (or to wherever §16 is actually defined — it's cited here and in CHANGELOG.md/fingerprint_client.py/smoke_test.py but doesn't appear to exist anywhere in this repo's docs). If they're illustrative/hypothetical, the comment shouldn't be phrased as a factual incident report.

# you fix one, check the siblings.
.env*
!.env.example
Loading