Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Never Commit Secrets Again

x2y GitIgnore Generator

v1.0.0

The essential security companion for modern developers. Whether you are working in Python, Node.js, React, or C++, ensuring your sensitive data stays out of your public repositories is critical. Generate the perfect .gitignore file in seconds and audit existing projects for dangerous exposures.

WINDOWS20+ TEMPLATESREPO SCANNINGZERO TELEMETRY

Free — no account, no cloud lookup, no telemetry. Templates ship with the app and work entirely offline.

At a glance

  • Versionv1.0.0
  • PlatformWindows
  • Templates20+ bundled offline
  • AuditUnignored-file scanning
  • OutputClipboard or atomic write
  • PriceFree

Templates are bundled locally and never fetched over the network — so it works on a plane, in a lab or on a fresh machine.

Key features

Stop the "Oops, I committed my .env" nightmare

Generate the perfect .gitignore in seconds

Select your stack from curated templates, preview the merged output in real time, and write directly to your repository root. The generator combines rules intelligently — no duplicates, no conflicts, no manual editing required.

Audit existing projects for dangerous exposures

Point the scanner at any repository and it identifies files that should be ignored but are not — .env files, API keys, credentials, build artifacts, OS metadata and editor swap files. Catch the exposure before it reaches a remote.

Save custom templates for reuse

Build your own template combinations and save them for future projects. Export and import templates as portable files so your team shares the same ignore standards across every repository.

Copy to clipboard or save directly

Generate the output and copy it to your clipboard with one click, or write it atomically to the target directory. The diff preview shows exactly what will change before anything is written — no surprises.

Supported templates

20+ curated templates covering every major stack

Each template is maintained and updated locally within the application. No network fetch is required — the full template library ships with the installer and works in air-gapped environments.

Node.jsPythonReactVueAngularPHPRubyRustC++C#JavaGoSwiftKotlinmacOSWindowsLinuxVSCodeVimIntelliJSublime TextUnityUnreal Engine

Specifications

Technical details

x2y GitIgnore Generator specifications
Productx2y GitIgnore Generator
Versionv1.0.0
PlatformWindows
Templates20+ curated (languages, frameworks, editors, OS)
Template storageBundled locally — no network fetch
Repository scanningDetects unignored sensitive files
Audit targets.env, API keys, credentials, build artifacts, OS metadata, editor swaps
Custom templatesCreate, save, export, import
OutputCopy to clipboard or atomic file write
Diff previewShows changes before writing
Merge logicDeduplication and conflict resolution
Telemetry0 bytes — verified continuously
Account requiredNone — ever
PriceFree
Developerx2y Devs Tools Ltd, Nairobi, Kenya

Quick start

From install to protected repo in four steps

  1. 01

    Install

    Download from Microsoft Store, itch.io or Uptodown. Run the installer — no administrator privileges required for standard installs. No account creation, no activation key.

  2. 02

    Select your stack

    Open the Generate tab and check the templates that match your project — Node.js + VSCode + macOS, for example. The preview pane updates in real time as you toggle templates.

  3. 03

    Audit an existing repo

    Switch to the Audit tab and point it at a repository. The scanner identifies files that should be ignored but are not — .env files, credential stores, build outputs — and flags them by severity.

  4. 04

    Write or copy

    Review the diff preview, then write atomically to the repository root or copy the output to your clipboard. Save the template combination for reuse on future projects.

Already committed a secret? Adding a .gitignore rule does not remove a file from Git history. If a secret was already pushed, rotate the credential immediately and use git filter-repo or BFG Repo-Cleaner to purge it from history. The Code Leak Detector can help identify what was exposed.

Downloads

Get x2y GitIgnore Generator v1.0.0

Verify before installing. Every release is signed. Compare the published checksum on the release page against your downloaded file before running the installer.

Changelog

Release history

2026v1.0.0

Initial release. 20+ curated templates covering Node.js, Python, React, Vue, Angular, PHP, Ruby, Rust, C++, C#, Java, Go, Swift, Kotlin, macOS, Windows, Linux, VSCode, Vim, IntelliJ, Sublime Text, Unity and Unreal Engine. Repository scanning for unignored sensitive files (.env, API keys, credentials, build artifacts, OS metadata, editor swaps). Custom template creation, save, export and import. Real-time merge preview with deduplication. Atomic file write with diff preview. Copy-to-clipboard output. Built-in help guide. 100% offline — all templates bundled locally.

Security model

Your repository structure is nobody else's business

Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Repository scanning: reads only the directories you explicitly select. Template library: bundled locally, never fetched from a server. Network connections: none — the application makes zero outbound connections under any circumstance. Licence: free.

x2y GitIgnore Generator reads the file tree of the repository you point it at — that is its function. It does not transmit the file list, the generated .gitignore content, or any other data anywhere. The template library is embedded in the installer and exists entirely on your filesystem. There is no analytics SDK, no crash reporter, no licence verification call, no cloud sync. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections.

Security manifest
Telemetry0 bytes collected
AccountNone required — ever
Repo scanningOnly directories you explicitly select
Template libraryBundled locally, never fetched
Generated outputNever transmitted
NetworkZero outbound connections
VerificationAny network monitor

Why this file matters

A .gitignore is the cheapest security control in a repository

The failure mode is asymmetric

A missing entry costs nothing on Monday and everything on the day you open-source the repository. .env files, key pairs, database dumps and IDE swap files look like harmless local clutter right up until they are indexed by a search engine and swept by credential crawlers.

Ignoring files is not a formatting preference; it is the first line of defence for secrets. That is why this generator treats an existing repository as a first-class input, not an afterthought: generate the file, then audit what is already tracked.

Stacking templates is where mistakes hide

Real projects are a stack: Node plus React plus VS Code plus macOS, or Python plus Django plus PostgreSQL. Choosing one template is how half the gaps appear. The generator lets you select several, merges them with deduplication and conflict resolution, and shows a diff preview before it writes — so you can see what changed instead of trusting a paste.

All 20-plus templates ship inside the app. Nothing is fetched from a gist or a repository at runtime, which means the output is reproducible and works with the network cable out.

Auditing an existing project

The scanner walks a repository for the exposures that survive a good intention: unignored .env files, API keys and credential material, build artefacts, OS metadata like .DS_Store and editor swap files. It reports what should be ignored and, importantly, what is already tracked.

Tracked files are the trap. Removing a path from tracking with git rm --cached stops future commits from including it; it does not erase it from history, and it does not make a committed credential safe. Rotate the credential, then decide how much history you must actually rewrite.

Custom templates, kept local

Your stack is probably not in any public list: the internal SDK folder, the licence file that must never ship, the generated client directory. Create a custom template, save it, export it to a colleague, import it on the next machine. It stays on disk as a plain file you can diff and version.

Atomic writes and a copy-to-clipboard output cover both habits: let the tool write the file with a previewed diff, or take the text and paste it into your own commit.

How it works

Generate for a new repo, audit an old one

01

Select your stack

Tick the languages, frameworks, editors and operating systems in play. The merge step deduplicates and resolves conflicting rules.

02

Preview the diff

For a new file, read what will be written. For an existing .gitignore, the diff shows exactly which lines are added or changed before anything touches disk.

03

Audit the working tree

Run repository scanning to find unignored sensitive files and build artefacts that survived a previous ignore — including files already tracked.

04

Write or copy

Atomic file write or clipboard copy, your choice. Save the combination as a custom template for the next project in the same stack.

Technical summary
Template scopeLanguages, frameworks, editors, OS, IDEs
Merge behaviourDeduplication with conflict resolution
Audit targets.env, keys, credentials, artefacts, OS and editor noise
Write modeAtomic write with diff preview, or clipboard
Custom rulesCreate, save, export, import as plain text
OfflineEvery template bundled in the app
Ignore files, then verify the ignore worked. After writing the file, run git status --ignored in the repository to confirm your sensitive paths are listed as ignored. If a file was already tracked, git rm --cached it and rotate any credential it contained.

Who it is for

Every repository you expect to outlive your own attention

Open-source authors

The moment a private repository turns public is the moment every tracked secret is collected. Generate and audit before you flip the switch.

Agencies and consultants

One custom template per client stack, exported and versioned, so the next project starts from your standard rather than a stranger's gist.

Teams shipping mobile and game builds

Unity and Unreal directories, keystores and provisioning profiles are exactly the artefacts that must never be committed.

Security reviewers

A fast, offline check for exposure before a repository is shared, published or handed over.

Students and side projects

The habit costs a minute now and prevents the most common first-repository mistake there is.

Anyone cleaning up an old repo

Existing repositories are where the surprises are. The audit reads the tree you inherited and tells you what to fix first.

Prerequisites

What the tool needs and what it will not do

x2y GitIgnore Generator prerequisites
RequirementDetailsNotes
Operating systemWindows 10 or Windows 11No .NET or runtime prerequisite to install separately
RepositoryA folder containing your projectGit does not need to be initialised to generate the file
PrivilegesStandard user accountWrites only where you have file permissions
NetworkNoneTemplates are bundled; nothing is fetched at runtime
Existing .gitignoreRead, diffed, mergedNever overwritten silently — the diff preview shows the change
History rewritingOut of scope, deliberatelyRotate credentials first; history surgery is a git operation
VerificationPublished SHA-256 checksum per releaseCompare with PowerShell Get-FileHash before installing
Scope, honestly stated. This tool writes ignore rules and audits a working tree. It does not rewrite Git history, does not manage secrets and does not replace a secret scanner — those are three different jobs, and the suite covers all three.

Context

Desktop generator versus copy-pasting a template

Comparison of generated, pasted and manual ignore files
Concernx2y GitIgnore GeneratorOnline template collectionsHand-written .gitignore
Multi-stack mergeDeduplicates and resolves conflictsManual concatenation, duplicates and gapsWhatever you remembered
Audit of tracked filesBuilt inNoneNone
Works offlineFullyNeeds a browser and a fetchYes
Diff preview before writeYes, atomic writeCopy-paste and hopeYou are the diff
Reusing your own stackCustom templates, export and importYour bookmarks folderYour project templates
CostFreeFree, usually with adsYour time

Questions

Ignore files, secrets and history

Different in two ways. First, you can stack several templates and the tool merges them with deduplication and conflict resolution, which is where pasted collections usually fail. Second, the audit looks at the repository you already have. Downloading a good template never told you that .env was already committed.
No. Nothing in this tool rewrites history, and it should not be the first thing you reach for: rotate the credential immediately, then decide whether history needs surgery. git rm --cached stops future tracking; it does not remove the past.
No. It writes or copies the .gitignore text and reports findings. The audit is read-only, and any write goes through a diff preview with an atomic file write, so you always see the exact change first.
Scanning focuses on the exposures that matter: unignored .env files, key material, credential files, build artefacts, OS metadata and editor swaps. Ignored directories are not interesting — the question is always what is not ignored.
20-plus curated templates spanning Node.js, Python, React, Vue, Angular, PHP, Ruby, Rust, C++, C#, Java, Go, Swift, Kotlin, macOS, Windows, Linux, VSCode, Vim, IntelliJ, Sublime Text, Unity and Unreal Engine — all bundled in the app, so generation works offline.
Yes. Generate a root file from the union of the stacks in play, then save that combination as a custom template. Package-level .gitignore files still follow the usual Git rule that ignore patterns are evaluated per directory.
If a script already fits your workflow, keep using it. The desktop app exists for the other 90 per cent of cases: opening an inherited project, previewing a merge, auditing without cloning into a terminal, and doing it all on a machine with no network access.
Yes — donationware, like the rest of the suite apart from Code Leak Detector. No seats, no keys, no account. Optional contributions are what keep signing certificates and build infrastructure paid for: Support the project.

Documentation

Guides, templates and next steps

The pair that closes the loop. Code Leak Detector reads contents and finds a committed credential; this generator prevents the next one. Run the generator on a fresh repository and the detector on anything you inherited.

Ready to protect your repo

Download x2y GitIgnore Generator — generate, audit, and never leak again

No account. No telemetry. No cloud. Just a fast, offline tool that keeps your secrets out of Git history and your repositories clean.

Summary
Versionv1.0.0
PlatformWindows
PriceFree
Telemetry0 bytes