Ignore hardware-backed SSH key files in the canonical ignore files (closes #81)
check / check (push) Waiting to run
check / check (push) Waiting to run
`ssh-keygen` names the private key of a key backed by a hardware security key `id_ecdsa_sk` or `id_ed25519_sk`. The canonical `.gitignore` and `.dockerignore` listed only `id_rsa`, `id_dsa`, `id_ecdsa` and `id_ed25519`, so a repository could commit these files or copy them into an image. Both names are added beside their plain counterparts in each file's own style: unanchored in `.gitignore`, `**/`-prefixed in `.dockerignore`, case-folded with character ranges in both. A pattern matches the whole file name, so the `.pub` halves stay trackable and still reach the build context. Model: opus-5-5
This commit was merged in pull request #93.
This commit is contained in:
@@ -21,6 +21,10 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out
|
||||
`id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes
|
||||
for keys backed by a hardware security key (issue 81). Their `.pub` halves
|
||||
stay trackable.
|
||||
- 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so
|
||||
yarn no longer prints "No license field" when `script/bootstrap` runs it
|
||||
inside the Docker phases (issue 76). That was the only yarn warning there.
|
||||
|
||||
Reference in New Issue
Block a user