Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: dimalama/backup-scripts

Security

SECURITY.md

Security Guidelines

This repository is designed to be safe for public sharing. Follow these guidelines to ensure no sensitive information is exposed.

Files That Should NEVER Be Committed

The following files are automatically ignored by .gitignore:

1. Configuration Files

  • config.sh - Contains your specific paths and settings
    • Use config.template.sh as a template
    • Never commit your actual config.sh

2. User-Specific LaunchAgent Files

  • com.<username>.*.plist - Contains your username and absolute paths
    • Templates are OK: com.example.*.plist
    • Actual configured files should stay local

3. Documentation with User Info

  • SESSION_SUMMARY.md - May contain usernames, paths, timestamps
    • This file is generated per session
    • Reference the templates instead

4. Claude Code Settings

  • .claude/settings.local.json - Contains user-specific paths and permissions
    • Shared Claude configs are OK: .claude/claude.json, .claude/commands/*

5. Logs and Runtime Data

  • logs/ directory - Contains backup logs with timestamps
  • *.log files - May contain file paths and commit messages
  • .DS_Store - macOS metadata files

What IS Safe to Commit

Template Files

  • config.template.sh
  • com.example.backup-obsidian.template.plist
  • com.example.backup-personal-docs.template.plist

Scripts

  • All .sh files (they use template/variable paths)
  • lib/backup-functions.sh

Documentation

  • README.md
  • SETUP_GUIDE.md
  • TESTING_CHECKLIST.md
  • Other .md files (except SESSION_SUMMARY.md)

Shared Claude Configs

  • .claude/claude.json
  • .claude/commands/*.md

IDE Settings (if generic)

  • .vscode/settings.json (color themes, etc.)

Before Committing - Security Checklist

Run this before every commit:

# 1. Check git status
git status
# 2. Verify no sensitive files are staged
git diff --cached --name-only | grep -E "config.sh|com\.[^e].*\.plist|SESSION_SUMMARY|settings.local"# Should return nothing# 3. Check for hardcoded credentials
git diff --cached | grep -iE "password|api_key|secret|token"| grep -v "example"# Should return nothing# 4. Check for email addresses
git diff --cached | grep "@"| grep -v "example.com"# Should only show safe examples# 5. Check for absolute paths with usernames
git diff --cached | grep "/Users/"| grep -v "YOUR_USERNAME\|yourusername\|username"# Should return nothing

What to Do If You Accidentally Commit Sensitive Data

If not yet pushed:

# Remove the file from the last commit
git reset HEAD~1
# Or amend the commit
git commit --amend

If already pushed to GitHub:

# Remove file from git history entirely
git filter-branch --force --index-filter \
"git rm --cached --ignore-unmatch path/to/sensitive/file" \
--prune-empty --tag-name-filter cat -- --all
# Force push (⚠️ DANGEROUS - notifies all collaborators)
git push origin --force --all

Better approach: Use GitHub's support to purge the file:

  • Go to Settings > Support
  • Request sensitive data removal
  • GitHub will help clean the history

After removing:

  1. Update .gitignore to prevent future commits
  2. Rotate any exposed credentials
  3. Update remote repository URLs if needed
  4. Notify collaborators if this was a shared repo

Sensitive Data Types

❌ Never Commit

  • Usernames - Use placeholders like YOUR_USERNAME
  • Email addresses - Use your-email@example.com
  • Absolute paths - Use $HOME or /path/to/directory
  • Repository URLs - Use examples like https://github.com/yourusername/repo.git
  • API keys or tokens - Never, ever
  • Passwords - Obviously
  • Private git repository URLs - Shows repo names and organization

✅ Safe to Include

  • Generic examples - "your-email@example.com"
  • Template paths - "/path/to/backup-scripts"
  • Variable references - "$HOME", "$USER"
  • Public examples - GitHub repository structure

Git Configuration

Your .gitignore should include:

# User-specific configurationconfig.sh# User-specific launchd plist filescom.*.plist!com.example.*.plist # Allowtemplates# Session-specific documentationSESSION_SUMMARY.md# Claude Code settings.claude/settings.local.json# Log fileslogs/
*.log*.log.*# macOS.DS_Store# Backup files*.bak*~# Temporary files*.tmp*.swp

Regular Security Audits

Run these commands periodically:

# Find all tracked files
git ls-files
# Search for potential secrets
git grep -iE "password|api_key|secret|token" -- ':!SECURITY.md'# Find email addresses
git grep "@" -- ':!*.md'':!*.template.*'# Find absolute paths with usernames
git grep -E "/Users/[^/]+" -- ':!SECURITY.md'':!*.md'

Repository Settings

On GitHub, configure:

  1. Branch Protection

    • Require pull request reviews
    • Enable status checks
  2. Security Alerts

    • Enable Dependabot alerts
    • Enable secret scanning (GitHub Advanced Security)
  3. Collaborators

    • Review who has write access
    • Use teams for organization

Questions?

If you're unsure whether something is safe to commit:

  1. Check this SECURITY.md file
  2. Review .gitignore
  3. When in doubt, leave it out!

Remember: It's easier to add a file later than to remove it from git history.

There aren't any published security advisories