Secrets and protected paths
Understand the files and outputs RepoTunnel intentionally protects.
Guides follow the current project source. Check the release notes for your installed version.
Protected files
- .env and .env.* except example/sample/template variants
- Common SSH private-key filenames
- Common credential JSON files
- .npmrc, .pypirc, .netrc, .git-credentials and credentials.toml
- .pem, .key, .p12, .pfx, .jks and .keystore
Output handling
RepoTunnel redacts credential-like terminal/process output and does not intentionally log project source, API keys or raw credentials.
Never put credentials in project docs
Do not commit OAuth refresh tokens, private keys, ngrok/Cloudflare tokens or tunnel secrets into projects or website source. Provider credentials belong in the supported local configuration paths.
Protected-path filters, output redaction, Git secret scanning and restricted child-process environments each provide separate defenses; they do not make it safe to paste credentials into a public issue.
Check publish boundaries
RepoTunnel validates staged Git content and performs a final secret check before an explicitly authorized push. External Git clean filters and local hooks are restricted along controlled mutation paths.
If a suspected secret was ever published, revoke/rotate the credential at the provider. Simply removing a token from the latest commit may not remove it from remote history.