This is a public repository. Never commit secrets, credentials, or personal information.
The following files are automatically excluded from git:
config.yaml- Your actual configuration with real email addressessrc/config.yaml- Alternate location (both are ignored)
client_secret*.json- OAuth app credentials from Google Clouduser_credential*.json- Generated access/refresh tokens**/gmail-credentials/- Entire credentials directory
test-*.txt- Test email files you createtest-*.html- HTML test files you create
bin/,obj/- Build output directoriesnupkgs/- NuGet packages
These files ARE committed and visible to everyone:
example.config.yaml- Example configuration (no real credentials)- Source code files (
.cs,.csproj) - Documentation (
.mdfiles) .gitignoreitself
OAuth credentials are stored outside the repository in your user profile:
- Windows:
%APPDATA%\Notify.Console\gmail-credentials\{profile}\ - Unix:
~/.config/notify-console/gmail-credentials/{profile}/
These directories are:
- Outside the git repository
- User-specific
- Never committed to version control
- Secure from accidental commits
Before committing any changes:
- β
Check
.gitignoreincludesconfig.yaml - β
Use
example.config.yamlas a template only - β
Keep OAuth credentials in
%APPDATA%(Windows) or~/.config(Unix) - β
Run
git statusto verify no secrets are staged - β Never commit files with real email addresses or API keys
If you accidentally commit credentials:
- Revoke the credentials immediately at https://console.cloud.google.com
- Remove from git history:
# Remove file from git but keep locally git rm --cached config.yaml git commit -m "Remove accidentally committed config"
- For sensitive history, consider using
git filter-branchor BFG Repo-Cleaner - Create new credentials and update your
config.yaml
- Always use example.config.yaml as template - Copy it to
config.yaml - Never edit example.config.yaml with real data - Keep it generic
- Double-check before commits - Run
git statusandgit diff --staged - Use separate Google Cloud projects - For personal vs work profiles
- Rotate credentials periodically - Delete and recreate OAuth credentials
- Limit OAuth scopes - Only use
gmail.sendscope (notgmail.modify)
- β
.gitignoreconfigured to excludeconfig.yaml - β OAuth credentials stored in user profile directory (outside repo)
- β Example configuration has placeholder values only
- β Build artifacts excluded
- β Test files excluded
If you're unsure whether a file should be committed, check:
- Does it contain real email addresses? β Don't commit
- Does it contain API keys or OAuth credentials? β Don't commit
- Is it personal test data? β Don't commit
- Is it a generic example? β Safe to commit
When in doubt, don't commit it.