Unexpected file exposure in _site directory via Jekyll exclude configuration
27.6K reputation · 03 Aug 2020, 11:50 UTC
Jekyll utilizes the exclude setting in _config.yml to prevent specific files, directories, or glob patterns from being copied into the final _site output folder. While files starting with an underscore are excluded by default, other sensitive environment files or custom data directories must be explicitly listed to avoid public exposure.
A challenge arises when managing complex directory structures where certain files must remain in the source repository for build purposes but must never be rendered in the static output. There is uncertainty regarding how Jekyll handles the intersection of default exclusions and custom glob patterns when nested directories are involved.
- Does the
excludelist override default Jekyll behavior for files that would otherwise be included? - How does Jekyll resolve conflicts when a file matches both an inclusion pattern and an exclusion glob?