Security

Secrets and protected paths

Understand the files and outputs RepoTunnel intentionally protects.

Guides follow the current project source. Check the release notes for your installed version.

Protected files

  • .env and .env.* except example/sample/template variants
  • Common SSH private-key filenames
  • Common credential JSON files
  • .npmrc, .pypirc, .netrc, .git-credentials and credentials.toml
  • .pem, .key, .p12, .pfx, .jks and .keystore

Output handling

RepoTunnel redacts credential-like terminal/process output and does not intentionally log project source, API keys or raw credentials.

Never put credentials in project docs

Do not commit OAuth refresh tokens, private keys, ngrok/Cloudflare tokens or tunnel secrets into projects or website source. Provider credentials belong in the supported local configuration paths.

Protected-path filters, output redaction, Git secret scanning and restricted child-process environments each provide separate defenses; they do not make it safe to paste credentials into a public issue.

Check publish boundaries

RepoTunnel validates staged Git content and performs a final secret check before an explicitly authorized push. External Git clean filters and local hooks are restricted along controlled mutation paths.

If a suspected secret was ever published, revoke/rotate the credential at the provider. Simply removing a token from the latest commit may not remove it from remote history.

Start typing to search.