Cover more secret shapes in the canonical .gitignore (closes #38)
check / check (push) Successful in 26s
check / check (push) Successful in 26s
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`, so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as `ssh-keygen` writes it could all be committed. It now covers the same shapes as `.dockerignore`, written to `.gitignore`'s own rules: unanchored with no `**/` prefix, since an unanchored pattern already matches at every depth, and case-folded with character ranges because matching is case-sensitive on Linux. `example.env` and `sample.env` are re-included so a committed template stays trackable. Model: opus-5-5
This commit is contained in:
@@ -21,6 +21,11 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on
|
||||
secrets (issue 38): it now also ignores `prod.env`-style `*.env` files,
|
||||
`.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to
|
||||
`.gitignore`'s own rules (no `**/` prefix) and case-folded with character
|
||||
ranges. `example.env` and `sample.env` stay trackable through negations.
|
||||
- 2026-10-02: The image version now comes from git inside the build (issues 69
|
||||
and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical
|
||||
`.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a
|
||||
|
||||
Reference in New Issue
Block a user