7 .htaccess
@@ -10,6 +10,13 @@
Deny from all
+# This denies access to all yml files, since developers might include sensitive
+# information in them. See the docs for work-arounds to serve some yaml files
+<Files *.yml>
+ Order allow,deny
+ Deny from all
ErrorDocument 404 /assets/error-404.html
ErrorDocument 500 /assets/error-500.html

