Skip to content

Conversation

@digitaldirk
Copy link
Contributor

Added a warning about forking the repository for production use, as we do not want users to accidentally leak private keys.

Added a warning about forking the repository for production use.
@linkdotnet
Copy link
Owner

Hey @digitaldirk - Thanks for raising the PR.

I don't think the message sits right with me, for some reasons:

  1. While true - you can't directly set it to private, there are easy workarounds.
  2. Even then: Forking isn't a "production concern". Even in a private repo, you might wanna take care of those things (especially in case of you want to make it public later on).
  3. Even if we assume all of the above doesn't matter: A README advice is probable not safe (or it is almost safe to assume folks don't read it)

We already "gitignore" the environment appsetting files - that is idiomatic to what .NET does.
As long as you follow the basic principles, you should be fine.

@linkdotnet
Copy link
Owner

PLUS: We have some scanning stuff in place like CodeQL which would inform you, if you would leak (even though it might be too late then - you can and should rotate secrets)

@digitaldirk
Copy link
Contributor Author

@linkdotnet Makes sense, thank you for the details in your reasoning :)

@digitaldirk digitaldirk deleted the add-fork-warning branch December 22, 2025 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants