Other dotfiles that leak: .aws/credentials, .svn and .DS_Store.
Files and folders whose names start with a dot are hidden on your own machine, so they get uploaded without anyone noticing. The web server doesn’t hide them. Besides .env and .git, DotenvScan checks three that turn up often.
.aws/credentials
The AWS command line and SDKs keep access keys in ~/.aws/credentials. When a home directory is the web root, or a project carries its own .aws folder, /.aws/credentials serves those keys to anyone.
- Deactivate the key now in IAM, create a replacement, deploy it, then delete the old one. Leaked AWS keys are often abused within minutes, typically to start compute instances for crypto mining.
- Review CloudTrail for anything the old key did, and your bill for resources you didn’t create — in every region.
- Stop using stored keys on servers. On EC2, give the instance an IAM role instead; elsewhere, keep credentials outside the web root.
.svn
Since Subversion 1.7, each checkout has one .svn folder at its root, holding wc.db — a database listing every file — and pristine/ copies of their contents. With both reachable, your source can be rebuilt, just like an open .git directory.
- Block it (below), then deploy with
svn export, which writes a clean copy without any.svn, instead ofsvn checkout. - Rotate every secret that was ever committed to the repository.
.DS_Store
macOS writes a .DS_Store into folders opened in Finder, recording the names of the files in them. Uploaded with the site, it tells anyone the names of files you never linked to — backups, database exports, admin scripts — and free tools read it automatically.
- Look at what it names: if a backup or export is listed, remove that file too.
- Delete them from the server:
find /var/www -name .DS_Store -type f -delete. - Keep them out of deploys: add
.DS_Storeto.gitignore, or--exclude=.DS_Storeto rsync.
One rule for all of them
The blocking rules in the main guide refuse every dotfile and dot-folder on nginx, Apache and Caddy — .env, .git, .svn, .aws and .DS_Store alike — while leaving /.well-known/ working for HTTPS certificates.