Security and privacy
No account, no telemetry
Section titled “No account, no telemetry”dotfix has no backend. It talks to Homebrew, to Git, and to your secret provider — nothing else. There is no account, no usage reporting, and no network connection you did not configure.
Secrets are never stored
Section titled “Secrets are never stored”A template references a secret by name. The value is resolved on the machine when the file is rendered and is never written to the repository. dotfix redacts resolved values from its own output, including the diff view in the app.
Two refusals protect this:
- A file rendered from a template that resolves a secret is not written back into the repository. The copy on disk holds the real value, so writing it back would commit the secret and replace the placeholder with it.
- Adopting a file whose name suggests it is itself a credential — an SSH private key,
.netrc,.aws/credentials— is refused, with a suggestion to use a secret reference instead.
File permissions
Section titled “File permissions”A rendered file that resolved a secret is written 0600. Other managed files are written 0644.
Host key pinning
Section titled “Host key pinning”When setup needs to add GitHub to your known_hosts, it does not trust whatever answers. It scans the key, compares the fingerprint against GitHub’s published values compiled into dotfix, and writes nothing on a mismatch.
An entry written with HashKnownHosts yes is recognised as well, so a host you already trust is not pinned a second time.
What your repository reveals
Section titled “What your repository reveals”Keep it private. Even with no secrets in it, the list of packages you have installed says a good deal about what you work on, and machine names and template variables often carry your email address or employer.
Deploy keys
Section titled “Deploy keys”A deploy key dotfix generates has no passphrase — an hourly background job has no terminal to type one into. It is scoped to a single repository, so it opens your dotfiles and nothing else. If that trade is not acceptable, use an SSH key you unlock yourself and accept that the background check will not reach the remote.