From 7ea5cdcdcd85004952f0799033121d41300de906 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sat, 3 Oct 2026 17:39:40 +0200 Subject: [PATCH] Cover more secret shapes in the canonical .gitignore (closes #38) The canonical .gitignore matched only .env, .env.*, *.pem and *.key, so prod.env, .envrc, *.p12 and *.pfx bundles, and the SSH private keys id_rsa, id_dsa, id_ecdsa and id_ed25519 could be committed. The secrets section now covers the same shapes as the canonical .dockerignore, written to gitignore's own rules: unanchored, no **/ prefix, character ranges for case. example.env and sample.env stay trackable through negations, and the comment tells a repository to add its own negation for any other committed template. Judgement call: the existing entries were rewritten with character ranges, which only widens them, and the bare .env line is dropped because *.env covers it. Model: opus-5-5 --- .gitignore | 28 +++++++++++++++++++++++----- TODO.md | 5 +++++ 2 files changed, 28 insertions(+), 5 deletions(-) diff --git a/.gitignore b/.gitignore index 3558b76..4c335ba 100644 --- a/.gitignore +++ b/.gitignore @@ -20,8 +20,26 @@ Thumbs.db # Node node_modules/ -# Environment / secrets -.env -.env.* -*.pem -*.key +# Secrets. Unanchored like every entry above, so each matches at every +# depth. Matching is case-sensitive on Linux, so names use character +# ranges rather than a lowercase form that misses `Server.Key`. + +# Environment files. `*.env` covers bare `.env` and the `prod.env` +# convention. Only the templates `example.env` and `sample.env` are +# re-included below. A repository that commits any other template adds +# its own negation after these lines, for example `!.env.example`. +*.[eE][nN][vV] +.[eE][nN][vV].* +.[eE][nN][vV][rR][cC] +!example.env +!sample.env + +# Private keys and the bundles carrying them. +*.[pP][eE][mM] +*.[kK][eE][yY] +*.[pP]12 +*.[pP][fF][xX] +[iI][dD]_[rR][sS][aA] +[iI][dD]_[dD][sS][aA] +[iI][dD]_[eE][cC][dD][sS][aA] +[iI][dD]_[eE][dD]25519 diff --git a/TODO.md b/TODO.md index 2a27314..f41f0b3 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,11 @@ fmt-check, and commit. # Completed Steps +- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on + secrets (issue 38): it now also ignores `prod.env`-style `*.env` files, + `.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to + `.gitignore`'s own rules (no `**/` prefix) and case-folded with character + ranges. `example.env` and `sample.env` stay trackable through negations. - 2026-10-02: The image version now comes from git inside the build (issues 69 and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical `.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a