Repositories, remotes and signing in
Create and clone repositories, authenticate safely with SSH keys or tokens, and set up .gitignore, a license and a README.
- Create a repository on GitHub and connect it to a local one with remotes
- Choose between HTTPS with a token and SSH keys, and keep credentials safe
- Set up the files every repository needs: README, .gitignore and LICENSE
There are two ways to start:
- GitHub first: click New repository, then
git cloneit to your machine. - Local first: you already have a Git repository; create an empty one on GitHub and connect it with a remote.
1# 1. GitHub first
2git clone git@github.com:dungeon-dash/dungeon-dash.git
3cd dungeon-dash
4
5# 2. Local first: connect an existing repository, then push
6git remote add origin git@github.com:mira/level-editor.git
7git branch -M main
8git push -u origin main # -u remembers origin/main as the upstream
9
10git remote -v # list remotes and their URLsorigin is just the conventional name for “the GitHub copy”. After push -u, a plain git push or git pull on that branch knows where to go.
Proving who you are
Reading a public repository needs no login, but pushing does. GitHub stopped accepting account passwords for Git in 2021. You have two good options:
| HTTPS + token | SSH key | |
|---|---|---|
| URL looks like | https://github.com/OWNER/REPO.git | git@github.com:OWNER/REPO.git |
| Secret | a personal access token (fine-grained tokens can be limited to specific repos and permissions) | a private key file that never leaves your machine |
| Setup | create a token, let a credential manager (or gh auth login) store it | ssh-keygen -t ed25519, then add the public key to GitHub |
Either is fine. What matters: the private half of a key and every token are secrets. Never commit them, never paste them in issues, and give tokens only the permissions and expiry they need.
ssh-keygen -t ed25519 -C "mira@example.com" # creates ~/.ssh/id_ed25519 and id_ed25519.pub
cat ~/.ssh/id_ed25519.pub # paste THIS (the .pub) into GitHub → Settings → SSH keys
ssh -T git@github.com # "Hi mira! You've successfully authenticated..."Files every repository needs
- README.md - the front page: what the project is, how to install and use it, how to contribute. GitHub renders it under the file list.
- .gitignore - patterns for files Git should never track: build output, dependencies (
node_modules/), editor settings, and anything secret like.env. - LICENSE - without one, nobody else may legally reuse your code, even if it’s public. (More in the open-source lesson.)
1# build output and dependencies
2build/
3node_modules/
4*.pyc
5
6# secrets - never commit these
7.env
8*.pem
9
10# but keep this one example file
11!.env.example
12
13# only the save files in the repository root
14/saves/The rules, simplified: a pattern without a slash matches a file or folder name anywhere; a trailing / matches only folders; a leading / anchors to the repository root; ! re-includes something an earlier pattern ignored; and the last matching rule wins. .gitignore only affects untracked files - if a file is already committed, ignoring it later changes nothing until you git rm --cached it.
Key takeaways
Clone a GitHub repo, or connect a local one with
git remote add origin ...andgit push -u.Authenticate with an SSH key or an HTTPS token - never a password - and treat both as secrets.
Revoke leaked tokens immediately; removing them from the code isn’t enough.
Every repo needs a README, a .gitignore (last matching rule wins) and a LICENSE.
Lesson quiz
7 questions · pass with 5 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Practice: automate GitHub chores with Python
Real GitHub work involves lots of small automation: matching CODEOWNERS, expanding build matrices, bumping versions, reading the API. Write those helpers in Python and run them against sample inputs - locally in your browser, with no GitHub account needed.
Convert remote URLs
A new contributor can’t push because they cloned with the wrong URL type. Each input line is to-ssh URL or to-https URL. Print the converted remote URL; both forms must end with .git:
https://github.com/dungeon-dash/dungeon-dash.git <-> git@github.com:dungeon-dash/dungeon-dash.gitThe input URL may be in either form, with or without .git.
- Both directions
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Would Git ignore it?
Implement a simplified .gitignore. The input has the patterns, a line ---, then file paths (relative to the repository root, with / separators). For each path print ignored or kept. Rules:
- A pattern without a
/(ignoring a trailing one) matches the name of the file or of any folder in its path, using shell wildcards (fnmatch). - A pattern ending in
/matches only folders. - A pattern starting with
/is anchored: it matches the path from the root (the start of the path). - A pattern starting with
!re-includes what it matches. - The last matching pattern wins; nothing matching means kept.
- Dungeon Dash rules
- Last rule wins
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…