From 567944f8d8a1cadf99b226fb8895f0459a962d39 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 09:14:52 +0200 Subject: [PATCH] Ignore hardware-backed SSH key files in the canonical ignore files (closes #81) `ssh-keygen` names the private key of a key backed by a hardware security key `id_ecdsa_sk` or `id_ed25519_sk`. The canonical `.gitignore` and `.dockerignore` listed only `id_rsa`, `id_dsa`, `id_ecdsa` and `id_ed25519`, so a repository could commit these files or copy them into an image. Both names are added beside their plain counterparts in each file's own style: unanchored in `.gitignore`, `**/`-prefixed in `.dockerignore`, case-folded with character ranges in both. A pattern matches the whole file name, so the `.pub` halves stay trackable and still reach the build context. Model: opus-5-5 --- .dockerignore | 2 ++ .gitignore | 2 ++ TODO.md | 4 ++++ 3 files changed, 8 insertions(+) diff --git a/.dockerignore b/.dockerignore index 351278b..d911b03 100644 --- a/.dockerignore +++ b/.dockerignore @@ -44,7 +44,9 @@ **/[iI][dD]_[rR][sS][aA] **/[iI][dD]_[dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA] +**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK] **/[iI][dD]_[eE][dD]25519 +**/[iI][dD]_[eE][dD]25519_[sS][kK] # Dependencies: restored inside the image, never copied in. **/node_modules diff --git a/.gitignore b/.gitignore index 4c335ba..534d4e2 100644 --- a/.gitignore +++ b/.gitignore @@ -42,4 +42,6 @@ node_modules/ [iI][dD]_[rR][sS][aA] [iI][dD]_[dD][sS][aA] [iI][dD]_[eE][cC][dD][sS][aA] +[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK] [iI][dD]_[eE][dD]25519 +[iI][dD]_[eE][dD]25519_[sS][kK] diff --git a/TODO.md b/TODO.md index 769cf3a..ad4785c 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,10 @@ fmt-check, and commit. # Completed Steps +- 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out + `id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes + for keys backed by a hardware security key (issue 81). Their `.pub` halves + stay trackable. - 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so yarn no longer prints "No license field" when `script/bootstrap` runs it inside the Docker phases (issue 76). That was the only yarn warning there.