Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How can I stop Cursor from sending .env files with secrets as plain text? Nothing I tried from the docs works.



This is a huge issue that was already raised on their forums and it's very surprising they didn't address it yet.

[0] https://forum.cursor.com/t/environment-secrets-and-code-secu...


I have been adding .env files to .cursorignore so far.

I can see from that thread that the approach hasn’t been perfect, but it seems that the last two releases have tried to address that :

“0.46.x : .cursorignore now blocks files from being added in chat or sent up for tab completions, in addition to ignoring them from indexing.”


lol "move fast and break stuff....like really, really break stuff. i mean, break it so bad you'll probably cause people to lose their jobs and livelihoods"




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: