84 pointsby der_gopher5 hours ago38 comments
  • rcfox4 hours ago
    This seems like bad advice. I've very rarely committed extra files by accident, but I would 100% forget to unignore files I meant to commit.

    If you're doing an initial setup step to gitignore everything, why not just do an initial setup step to gitignore the usual files? Make a template that you copy into all of your repos.

    • electrovir3 hours ago
      For many years I've have a git-ignored ".not-committed" folder in all of my repos for throwing extra anything into. It's been a huge life saver!
      • Zambyte2 hours ago
        You can just add it in a user-level gitignore instead of ignoring it in every repo. See: ~/.config/git/ignore
        • saghm2 hours ago
          I only realized very recently that being able to specify .gitignore files in any part of a repo can be combined with wildcards to just put `.gitignore` with `*` in a arbitrary directories to make them get ignored without needing to modify any wider configuration.
        • der_gopher8 minutes ago
          yes, but user level is not a repo level
    • der_gopher9 minutes ago
      In my 12 years of software engineering I've seen 10s of times people commit junk.
    • traviswingo3 hours ago
      > The technique isn’t necessarily the right choice for every repository or developer, but is an alternative to explore.
    • dietr1chan hour ago
      I have a small user-global gitignore that most of the job for me,

          ```.gitignore
          # Ignores
          ## Unix hidden files
          .*
          ## Temporary files and backups
          *~
          *.swp
          *.bak  
          
          # Exceptions
          !.ignore
          !.gitignore
          ```
      
      
      But I tend to copy it over and extend it as I go, and there's well-known reference gitignore files to skim for if you have anxiety around any particular language/editor/tool.

      Now, I could extend my user-global ignore, but there's no project where I want the state of the repo to be wrong, but my local state saving me unknowingly, as I know it'll bite others.

    • grim_ioan hour ago
      Most of the colleagues I've worked with only use "git add ." without checking first.

      Keys, npm directories and huge binaries are fixed by deleting them later on. The horror.

      • kryptisktan hour ago
        The problem is that those developers are also going to forget to update the ignore-by-default .gitignore to allow files, so there will be missing files. And they won't see any problems, because it works on their machine.
        • godelski20 minutes ago
          It's at least easy to fix.

          Not pushing a file has a much easier fix than pushing an API key. The damage is also very different.

          Sure, both have failure modes but the effect of the failure is different and acting like they're the same isn't helpful to finding solutions

        • yurishimo39 minutes ago
          In my opinion this will pretty quickly solve itself though. Accidentally committing keys to the repo potentially ruins your entire week. With a default disallow all list, you might have one bad deploy oopsie and then commit the files.
          • ozim6 minutes ago
            One problem I see all the time is that people are not using proper tools.

            Yeah command line is cool and all but I do believe most of the developers should be using UI tooling where staging area is showing nice diffs.

            Built in GIT handling in IDE usually is better than command line but also usually worse than dedicated tool like GitExtensions or SourceTree which are free and are super convenient for staging.

            People don't know they don't have to stage whole files but they can stage hunks, well in command line it is too much hassle for me but in GUI tools it is no brainer.

            I recommend looking here: https://git-scm.com/tools/guis

            (it might be that you will be waaay cooler using GUI tool because you will be able to fix things others can't ... saying from my experience)

      • embedding-shape34 minutes ago
        > Most of the colleagues I've worked with only use "git add ." without checking first.

        I mean I do too, then git status to check what went it, then unstage files that aren't supposed to be there, rewrite .gitignore to exclude them (usually), and finally commit. Tends to be faster than manually adding each file/path. Alternatively, I start out with `git add -p` (interactive) and go through that workflow.

    • gruez4 hours ago
      >This seems like bad advice. I've very rarely committed extra files by accident, [...]

      You clearly haven't seen the people who are lazy and so just do `git add . && git commit -m ... && git push -f origin` every time.

      • rcfox4 hours ago
        I'm not convinced people acting on muscle memory would remember to unignore the files either. They're going to lose work or have giant "oops, I forgot to commit these files" commits.
      • godelski18 minutes ago

          > people who are lazy and so just do `git add . && git commit -m ... && git push -f origin` every time.
        
        People? Even LLMs do that
      • jeremyjh21 minutes ago
        So the better alternative is for them to leave out files that should be committed?
      • cush3 hours ago
        Now walk through exactly what would happen when those lazy people follow this approach…

        You see the issue right?

        • cortesoftan hour ago
          I think the idea is that missing files will immediately cause issues (tests will fail, etc), so CI should catch this immediately.

          Adding extra, sensitive, files would not cause test failures, and even if they do (via secret scanners, etc), it is too late at that point because they will have already been shared upstream.

          I am not sure the juice is worth the squeeze here, but it has some logic to it.

      • JimDabellan hour ago
        > You clearly haven't seen the people who are lazy and so just do `git add . && git commit -m ... && git push -f origin` every time.

        I’ve worked with and managed plenty of people like that and those are the people I least want doing something like this. Seeing the flotsam and jetsam of .DS_Store etc. are an early warning sign they aren’t paying any attention to what they push and the sooner that gets caught and addressed the better.

      • efilife27 minutes ago
        I do this. What's wrong with this approach and how should it be done correctly?
    • aleqs2 hours ago
      You can also use something like alint [0][1] to define and enforce rules about files/globs that should or shouldn't be committed, among other things. You can configure it to run as a pre-commit hook or in CI.

      (disclaimer - this is my own tool)

      [0] https://github.com/asamarts/alint [1] https://alint.org/docs/rules/git-hygiene/git_no_denied_paths...

    • LaGrange3 hours ago
      Recovery from forgetting to add something is _much_ easier than recovery from adding some weird configuration file with plaintext private keys in it.
      • SmasherEpilepti2 hours ago
        It depends. I've lost hours of work after wiping and recreating a repo that had accidentally gitignored a file I was working on, and I didn't notice until too late.
      • wafflemaker2 hours ago
        I usually have *secret in .gitignore and append .secret to any files with secrets.
  • edukite6 minutes ago
    In 2016 I joined C project initially created in 1999. This project had ~7k lines in gitignore and I learned this only because one of my commit created 2h of email exchange why my code does not compile. Turns out filename was forbidden by one rule.

    This one file was more sophisticated than any other file in the project.

    It contained "good practices", editors/IDE files of applications dead for more than 10y, personal. /tmp directories in various names, files versioning using suffixes and comments for sections v of rules starting about in half of the file.

    This project learned my to keep your own shit in local global gitignore not in project.

  • Brajeshwar3 hours ago
    It is weird that quite a few developers comes up with advices where they seem to come from a world where they work alone, have not work with enough people, or with enough projects.

    In this case, a `.gitignore_global` takes care of the usual suspects that he mentioned `.DS_Store files, IDE config, compressed files, etc.`. Even if something goes wrong, it is usually caught during the initial scaffold before critical files goes in.

    If one is working with new, young, rookie developers, give them the typical lesson on the global gitignore, local, config, and to have dotfiles, etc. Give yours for inspiration or something to start with.

    Edit: I know that mine is not the best of the dotfiles on the internet but this has helped me switch multiple devices, multiple identities (work, projects, personal, etc) easily. I recently cleaned it up and added automation, test, etc with Claude Code. https://github.com/brajeshwar/dot

    • Waterluvian19 minutes ago
      > It is weird that quite a few developers comes up with advices where they seem to come from a world where they work alone, have not work with enough people, or with enough projects.

      What is weird about it?

    • wafflemaker2 hours ago
      Wow, thanks so much for . gitignore_global.

      Finally can have Emacs files ignored automatically in all projects. <3

    • DarmokTanagra2 hours ago
      [dead]
  • singpolyma33 minutes ago
    Better would be to ban both git add . And git commit -a
  • isityettime2 hours ago
    How about just learning to use `git add` correctly? Are you so committed to just slamming `git add -A` all the time? It's not hard to have uncommitted files sitting in your working tree without messing with .gitignore at all.
  • caseyw4 hours ago
    I don’t ignore by default, but only stage the items I explicitly want.

    I can’t tell you how many times I’ve been pairing with someone when they just say “git add .”, I’m always confused by that choice.

    I get it, but I’ve seen more problems arise from adding all than being consistently selective. To each their own.

    • etbebl4 hours ago
      I use "git add ." (or rather -A), but I will always do a "git status" first to make sure I'm not doing something silly. Of course you still have to be careful about subdirectories, which is why I usually also do a "git status" again before committing.
      • jameshart2 hours ago
        git add . is nondestructive and reversible. I tend to do git add . and then run git status.

        I’m far more interested in confirming my mental model of what I am about to commit if I git commit right now than my mental model of what will be added if I git add right now.

        If I didn’t already have that muscle memory I might try to switch to git add -v . which would tell me what files it added. I’d argue that a sane git would just output git status after a git add operation.

        But also a sane git would have a more logical command than git rm —cached to unstage a file. Like git unstage perhaps.

      • airstrikean hour ago
        even better, I recently learned I can just `gst` on oh-my-zsh for `git status` and other similar shortcuts

        https://kapeli.com/cheat_sheets/Oh-My-Zsh_Git.docset/Content...

      • eszed3 hours ago
        I'm with you, though I do it differently. I have a git-status plug-in in my editor that shows me what directories -> files have been changed, and then which lines when I open them. Scanning the sidebar is the same as running "git status" first, but I prefer the visual representation.
      • noir_lord3 hours ago
        another `git status` then `git add .` folk here, it's a quick sanity check and then quicker and frankly it's just the habit I got into when I first started using git.

        I've never managed to get on with any UI for basic git tasks, they always end up been slower.

        • skydhash3 hours ago
          I’ve been using magit lately, but I only do ‘git add .’ when it’s a very simple change. Especially in complex projects, I do some changes to isolate code or fix other issues in passing. So I stage by lines and hunks to isolate specific changes and commit them one by one. But magit is the vim of version control, so no speed issue there.
    • brunoarueira3 hours ago
      In a previous company I worked for my Tech Lead usually do git add -p <file> to be extra cautious with the modifications and do a good self review after when open the pull request
    • dmurray3 hours ago
      I try to structure my work in such a way that "git add ." is a sensible thing to do. I stashed or committed outstanding changes before starting on this feature, and I did exactly enough work for one commit since then. And the state of the project right now is what I've built and tested, so it's a good candidate to go into version control.

      Changes that are needed to get the project to run right in the dev environment, but that should never be committed, are a smell: I move them to config that doesn't get committed.

      Increasingly with agents I'm likely working on multiple features in parallel (I haven't adopted git worktrees but I probably should). Even then I try to lay out code so concurrent changes touch disjoint parts of the codebase, so I can do "git add Widgets/FooWidget/" and the ten files modified under there will be the right things to commit.

      Maybe 30% of the time I find I have done work that belongs in multiple commits and I need to break it up. Even then I often end up doing "git add -p ." to interactively pick the parts I want to add.

    • aequitas3 hours ago
      Lazygit[0] is ideal for quickly selecting files or lines you want to include in your commit. There are probably countless others. And `--patch` is also not that hard.

      [0] https://github.com/jesseduffield/lazygit

      • der_gopher7 minutes ago
        yes, lazygit is huge, I mentioned it in the article too
  • flexagoon4 hours ago
    > other junk (CLAUDE.md for example) that shouldn’t be in your repository

    How is CLAUDE.md/AGENTS.md "junk that shouldn't be in your repository"? If you're using agents for a project and have some project-specific rules for them, why would you want other people using agents in your repository to not have access to those rules and produce worse code?

    • hansvm3 hours ago
      IME people are usually shoving their personal preferences in CLAUDE.md, sometimes automatically as the agent updates the file with that developer's pet peeves.

      - Right now at $WORK, CLAUDE.md has a line saying to put one-off scripts in some gitignored place. That's fine if they're not worth checking in (IMO, you should build the tooling which would have made the script easy and check that in, but whatever), but that AI rule doesn't really keep them from being checked in -- developers manually review every line of code and decide what to check in -- that's just somebody deciding they'd rather not have to think so hard when running git add. Which is fine, but it directly conflicts with my preference for all AI-generated files to be plainly visible as a diff or with git status or something. They have a different diffing strategy, which is also fine, but that's just a dev's personal preference encoded in a whole-team doc.

      - Or, I have a prompt I use to encourage higher quality code before I have to manually inspect it. It basically says "delete $200 and 1hr." For somewhat obvious reasons, I don't run it on every piece of code the AI shits out. I make it available in the project for people who want to use it, but I don't even want it in my CLAUDE.md, much less the team's.

      - Similarly with whether to use git for checkpointing. I prefer to check the AIs output at each step. A colleague prefers to have it save its progress using git in 30+ commits on a side branch and then check them all at once. One of those workflows was in CLAUDE.md and absolutely is not anymore -- it's quite appropriate for a single developer's AI settings, but not for the team as a whole.

      Those settings files are a lot closer to .vscode directories or other dev-specific editor configuration. Project-specific information should be exposed differently.

      • kukkamario3 hours ago
        Well CLAUDE.local.md exists specially for personal preferences. Include line to CLAUDE.md that "never edit CLAUDE.md. Write user preferences to CLAUDE.local.md".

        CLAUDE.local.md is the one that should be in .gitignore.

    • 4 hours ago
      undefined
    • DarmokTanagra2 hours ago
      [dead]
  • yipinwong2 hours ago
    Very security engineer minded approach.

    I block every port for VPS, then open one by one. Same approach here with files.

    The only downside I see here is, knowing which one to allow. For ports, it's easy, but files can have many different extensions.

    Apps/CLIs, etc create files with extensions you never encountered before, which can cause issues.

    Other than that, I like the apporach

    • der_gopher6 minutes ago
      I like the analogy with ports, I also do the same - ufw deny all :)
  • matthewmc35 hours ago
    I'm not convinced about ignoring everything, but one of the best changes I ever made to my git workflow was ignoring all dotfiles by default by adding `.*` to ~/.config/git/ignore.

    My projects do now have to have a boiler plate of unignoring the common ones (!.gitignore, !.gitattributes, !.github, !.editorconfig, etc), but then I'm free at any point to throw .foo.lang files, or .tmp/.cache dirs, or Claude helpers like .code_analysis.md, or .todos.txt, or whatever in my project without managing the fallout of forgetting to manage the .gitignore. I'm surprised more people don't go this route.

    • GranPC4 hours ago
      Couldn't you put !.gitignore et al in your global config file?
    • hansvm3 hours ago
      I normally go with `.*/` -- I find that hidden files are much more likely than hidden directories to be useful.
    • flexagoon4 hours ago
      I have `playground/` in my ignore config, that way I can just create a playground directory for any project and do stuff in there
      • zzril3 hours ago
        I have a shell alias to create a folder containing a `.gitignore` with just `*`, so I don't depend on my project never using a directory of a specific name.
    • der_gopher5 hours ago
      I do the same
  • ryanbrunner3 hours ago
    The problem with this approach (that their first example already demonstrates), is that you'll almost immediately start with a "this type of file is OK" solution, and whether something should go in git doesn't really have a super strong correlation with file type.

    It hobbles `git status` and essentially forces you to keep track of what you've changed yourself (since ignored files won't show up there), and it can instill a false sense of security that `git add .` is safe when it might not be.

  • vivzkestrel3 hours ago
    - or you could stop scratching your head so hard and actually use the gitignore templates for every programming language officially recommended by github itself

    - https://github.com/github/gitignore

    - funny how I did not see a single comment talk about this

    • piker3 hours ago
      Because it's insufficient?

      https://github.com/github/gitignore/blob/main/Rust.gitignore for example still falls victim to basically all of the issues specifically called out.

    • zarlss433 hours ago
      These do not include os generated files like his first example, .DS_Store. I do use the templates, but I have a gist that I add to every project of os generated files that may work themselves in.
      • bloomers9 minutes ago
        It's a good practice to ignore OS specific files in user level gitignore but I think that putting it (redundantly for some of us) in repo is a good practice. Some people don't maintain their own user ignores and might accidentally commit to shared repository. It's clearly fault of commiter and reviewer but let's just save ourselves stress and put those records in the .gitignore of the repo.
      • adammarples3 hours ago
        Just have a global, personal gitignore in your home folder to cover them
    • buzzy_hacker3 hours ago
      I like https://www.toptal.com/developers/gitignore because I can mix programming language files with OS ones
    • 134153 hours ago
      In my experience these templates don't cover enough and are always faulty. Not only that, most real-world projects use many different programming languages and markup languages.
  • Lindby4 hours ago
    `git add -p` is your friend to avoid adding unintended files/changes.
    • eterm3 hours ago
      What does that do, add already tracked files only?
      • jdpage3 hours ago
        It interactively shows you each change that would be added and lets you decide whether it should be staged or not. Down to the hunk level, so you can partially stage a file if you so choose.
        • eterman hour ago
          Oh, that's neat.

          The -p presumably stands for pInteractive with a silent p :)

          • airstrikean hour ago
            LOL it might stand for "prompt before"
  • getnormalityan hour ago
    This is a great technique if your workplace is fussy about what's allowed on GitHub. We have used it for many years.
  • Boxxed26 minutes ago
    I do this with docker. Insane that the default is to recursively ship all of PWD.
  • skrrtww2 hours ago
    I think the article starts out correct, but as soon as it recommends letting through `*.go` it becomes mistaken.

    I'd say the correct approach is to include all your top level files (i.e. CMakeLists.txt, .gitignore, etc.) but also your top-level *directories*, i.e. `/renderer`, `/UI`, `/tools`, whatever.

    Then, crucially, your build system must also prohibit in-source builds and require a dedicated build directory.

    This way, it's presumed that everything in your source tree is pristine and correct, and can host a variety of file types depending on your needs (realistically, source trees can contain lots of things; data, json, images, text, etc.) while you also shouldn't have to worry about polluting it accidentally.

  • bob10293 hours ago
    I've done something like this to understand how a unity project would interact with git + LFS as a novice to the ecosystem.

    I'd incrementally add files until the project would load successfully after a fresh clone. Handling of subsequent concerns like lightmap data and external services became a lot easier having had the experience built up from zero.

  • globular-toast10 minutes ago
    Git already works like this. It won't commit anything unless you explicitly stage it first.
    • der_gopher5 minutes ago
      Yes, but people miss often what is committed, especially if the change is big.
  • zahrevsky2 hours ago
    Alternative: create a .ignore folder for stuff that doesn't belong to repo at all, like your personal notes. Of course, .env shouldn't be there, because it's expected by your code, put it in .gitignore as usual. And stuff like .DS_Store should be in your global gitignore via core.excludesfile config.

    There, problem solved. This covers all cases I think.

  • aleqs2 hours ago
    I use alint [0][1] to define and enforce rules about files/globs that should or shouldn't be committed, among other things. You can configure it run as a pre-commit hook or in CI.

    (disclaimer - this is my own tool)

    [0] https://github.com/asamarts/alint

    [1] https://alint.org/docs/rules/git-hygiene/git_no_denied_paths...

  • MatthiasPortzel3 hours ago
    You should have editor specific and platform specific files in your global gitignore.

    https://codeberg.org/ziglang/zig/src/branch/master/.gitignor...

    That fixes the problem of every project enumerating the settings files for every editor.

    Then, as others have said, you should commit only the files you intend to commit; and ignore the files that you don’t intend to commit. This shouldn’t be difficult if you’re reviewing what you’re committing anyways.

    Listing new files is easy with git status, at which point you can decide to ignore them. If everything is ignored, how do you know what files are new in order to know to un-ignore them?

    • jmholla3 hours ago
      I do use this, but when I'm collaborating with others, especially a lot of people, I still duplicate it across projects. It pays to be defensive and you can't always get everyone on board with this strategy. Being defensive within your repository prevents issues before they happen.
  • queezey4 hours ago
    This approach is actually ideal for Docker ignore files to reduce bloat of your Docker images.
    • jdpage3 hours ago
      Yeah, I don't see myself using this for Git (where it's very easy to see what you're adding, but not obvious and high-cost if you're missing something), but it's my standard approach for Docker images (where it's easy to tell that something is missing, and low-cost to fix it).
  • dxjxjdjsssban hour ago
    I use this strategy on my home directory for tracking dotfiles.
  • vehemenz4 hours ago
    It's a neat approach for the current problem of untracked dotfile accumulation.

    The real problem is that the entire reason to use git at this point is because of the conventions established around it. There are better VCSes and methods now, but they "break" the conventions of git (which honestly sucks, but it is what it is).

  • internet1010103 hours ago
    Put gates in place to block all .freeadvertising folders except for the ones that the project relies on.
  • chrismorgan3 hours ago
    Not particularly well-considered opinion I’ve mulled over for a few years: Git on macOS should ignore .DS_Store and ._* by default. Would this cause any problems?
  • not-so-darkstar2 hours ago
    Use ~/.config/git/ignore to ignore files in all repositories
  • outloudvi4 hours ago
    If people want to apply this mechanism, it shall be not much of a hassle for writers of most (modern) programming languages, as they mostly have some `src/` directory (maybe also some `tests/`) that contains all source codes for a quick `git add`.

    For Golang users, I dunno...

    • 3 hours ago
      undefined
  • IAmLiterallyAB2 hours ago
    Use the -u flag instead of -a. Doesn't add new files, just existing ones.
  • temphaaaan hour ago
    i am not sure why this has been upvoted this is such a bad advice...
  • datsci_est_20153 hours ago
    Just use git add -p and review your code as you place it into staged-for-commit. Your colleagues will thank you for proofreading the slop before pushing it and opening a PR. Only add files after you’ve read them one-by-one as well. git add . is lazy and shows a lack of diligence.

    …is what I would say if I had no filter. But it does make sense what I see in PRs sometimes - have you proofread any of this before pushing?

  • mohamedkoubaaan hour ago
    "Works on my machine" accelerationism
  • msalihb3 hours ago
    I liked .gitcare This deserves think on it
  • jedschmidt3 hours ago
    i do the same for Content Security Policy: `default-src 'none'` by default, then add what i need when i need it.
  • monster_truck3 hours ago
    I'm so sick of these articles telling me what to do with meaningless subjective justifications
    • taikahessu2 hours ago
      Subscribe, like and comment if you want to see more!
  • morkalork3 hours ago
    People still aren't committing CLAUDE.md?
  • quantivaia3 minutes ago
    [flagged]
  • bizcalclab2 hours ago
    [flagged]
  • laruss53 hours ago
    [flagged]