This repository handles sensitive device credentials and network information. Follow these security guidelines:
- NEVER commit actual credentials to version control
- Use
.envfiles for local development (already in.gitignore) - Set environment variables in CI/CD systems securely
WATTBOX_TEST_HOST=192.168.1.100 # Your Wattbox device IP
WATTBOX_TEST_USERNAME=wattbox # Device username
WATTBOX_TEST_PASSWORD=your_password # Device password
WATTBOX_TEST_PORT=23 # Telnet port (default: 23)
WATTBOX_TEST_TIMEOUT=10 # Connection timeout
WATTBOX_TEST_SCAN_INTERVAL=20 # Polling interval-
Copy the example file:
cp .env.example .env
-
Edit
.envwith your actual credentials:nano .env
-
Verify
.envis in.gitignore:git status # Should not show .env
- Use environment variables for all device connections
- Never hardcode IP addresses, usernames, or passwords
- Use example values in documentation and tests
- Store sensitive values as GitHub Secrets
- Use environment variables in GitHub Actions
- Never log sensitive information
If you accidentally commit sensitive information:
- Immediately change the exposed credentials
- Remove from git history:
git filter-branch --force --index-filter \ 'git rm --cached --ignore-unmatch .env' \ --prune-empty --tag-name-filter cat -- --all - Force push to remove from remote:
git push origin --force --all
- No hardcoded credentials in source code
-
.envfile in.gitignore - Environment variables used for all sensitive data
- Example values used in documentation
- CI/CD uses secure secrets management
- Regular credential rotation
To check for potential security issues:
# Search for hardcoded IPs
grep -r "192\.168\." . --exclude-dir=.git
# Search for potential passwords
grep -r "password.*=" . --exclude-dir=.git --exclude="*.md"
# Check for .env files
find . -name ".env*" -not -path "./.git/*"