Skip to content

Proposal: Revert checking-in of .envrc #16456

@jneen

Description

@jneen

Discussion

see #16263

As a long-time direnv user, I think it is best that the current checked-in .envrc file is deleted, or moved to .envrc.example or similar. Direnv was not designed to have its .envrc file checked in, as it is primarily intended for local environment overrides, and loading secondary files from .envrc causes a standing security issue, namely that secondary files are not hashed or checked for changes before sourcing.

I have already had my local .envrc clobbered by this change, and I don't currently have a way to restore my local environment overrides in a way that doesn't leave me with a standing diff.

Related discussions:


Add a 👍 reaction to issues you find important.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions