Cover more secret shapes in the canonical .gitignore (closes #38)
check / check (push) Successful in 26s

The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`,
so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as
`ssh-keygen` writes it could all be committed. It now covers the same
shapes as `.dockerignore`, written to `.gitignore`'s own rules:
unanchored with no `**/` prefix, since an unanchored pattern already
matches at every depth, and case-folded with character ranges because
matching is case-sensitive on Linux. `example.env` and `sample.env` are
re-included so a committed template stays trackable.

Model: opus-5-5
This commit is contained in:
2026-10-03 13:42:40 +00:00
parent 507a57e813
commit 717756df04
2 changed files with 27 additions and 5 deletions
+5
View File
@@ -21,6 +21,11 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on
secrets (issue 38): it now also ignores `prod.env`-style `*.env` files,
`.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to
`.gitignore`'s own rules (no `**/` prefix) and case-folded with character
ranges. `example.env` and `sample.env` stay trackable through negations.
- 2026-10-02: The image version now comes from git inside the build (issues 69
and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical
`.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a