Software developers often store secrets - passwords, tokens, API keys, and other credentials - in .env files within project directories. And if they do so, they're supposed to ensure that the .env file does not get posted in a publicly accessible .git repository. A common way to do this is to create an entry in a .gitignore file that tells the developer's Git software to ignore that file when copying a local repo to a remote server.
She looked calm, poised, and strangely familiar like the kind of woman you see once in a wedding magazine and never forget. She wore a plain blue gown and carried a small overnight bag.
"Shitty" may be a bit too vague; is he going to slut-shame your daughter? Call her out her name? Punch a hole in the wall? If you think his response will be in any way harmful or hurtful to your daughter (and/or you), then you shouldn't tell him.