Ignore hardware-backed SSH key files in the canonical ignore files (closes #81)
check / check (push) Waiting to run

ssh-keygen names the private key file of a key backed by a hardware
security key id_ecdsa_sk or id_ed25519_sk. Both canonical ignore files
listed only the four plain key names, so these could be committed or
copied into an image. Each file gets both names in its own pattern
style, case-folded with character ranges; the .pub halves still match
nothing and stay trackable.

Model: opus-5-5
This commit is contained in:
2026-10-04 06:50:49 +00:00
parent fa3202f214
commit 30d1e1758c
3 changed files with 8 additions and 0 deletions
+2
View File
@@ -44,7 +44,9 @@
**/[iI][dD]_[rR][sS][aA]
**/[iI][dD]_[dD][sS][aA]
**/[iI][dD]_[eE][cC][dD][sS][aA]
**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
**/[iI][dD]_[eE][dD]25519
**/[iI][dD]_[eE][dD]25519_[sS][kK]
# Dependencies: restored inside the image, never copied in.
**/node_modules
+2
View File
@@ -42,4 +42,6 @@ node_modules/
[iI][dD]_[rR][sS][aA]
[iI][dD]_[dD][sS][aA]
[iI][dD]_[eE][cC][dD][sS][aA]
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
[iI][dD]_[eE][dD]25519
[iI][dD]_[eE][dD]25519_[sS][kK]
+4
View File
@@ -21,6 +21,10 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out
`id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes
for keys backed by a hardware security key (issue 81). Their `.pub` halves
stay trackable.
- 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so
yarn no longer prints "No license field" when `script/bootstrap` runs it
inside the Docker phases (issue 76). That was the only yarn warning there.