Canonical ignore files miss the SSH key files for hardware-backed keys #81

Open
opened 2026-10-03 16:14:40 +02:00 by clawbot · 0 comments
Collaborator

Found in review of #80. Both canonical ignore files list the SSH private key names id_rsa, id_dsa, id_ecdsa and id_ed25519, but not id_ecdsa_sk and id_ed25519_sk, the names ssh-keygen writes for keys backed by a hardware security key. Those files still hold key material, so a repository can commit or ship one.

Fix

Add both names to the secrets section of the canonical .gitignore (gitignore rules: unanchored, no **/, character ranges for case, as the other key names there) and of the canonical .dockerignore (its own rules: **/ prefix, character ranges). Public halves (*.pub) must stay trackable. One commit, both files, plus any canonical sentence that lists the key names (git grep -n -i 'id_ed25519' -- .).

Start only after #80 has merged to next, since it rewrites the same .gitignore section.

Definition of done

  • In a scratch repository, git check-ignore -v reports both names ignored at the root and two directories deep, and id_ed25519_sk.pub is not ignored.
  • A scratch image built with the canonical .dockerignore does not contain either name at the root or two directories deep, and does contain id_ed25519_sk.pub.
  • make check passes.

Model: opus-5-5

Found in review of https://git.eeqj.de/sneak/prompts/pulls/80. Both canonical ignore files list the SSH private key names `id_rsa`, `id_dsa`, `id_ecdsa` and `id_ed25519`, but not `id_ecdsa_sk` and `id_ed25519_sk`, the names `ssh-keygen` writes for keys backed by a hardware security key. Those files still hold key material, so a repository can commit or ship one. ## Fix Add both names to the secrets section of the canonical `.gitignore` (gitignore rules: unanchored, no `**/`, character ranges for case, as the other key names there) and of the canonical `.dockerignore` (its own rules: `**/` prefix, character ranges). Public halves (`*.pub`) must stay trackable. One commit, both files, plus any canonical sentence that lists the key names (`git grep -n -i 'id_ed25519' -- .`). Start only after https://git.eeqj.de/sneak/prompts/pulls/80 has merged to `next`, since it rewrites the same `.gitignore` section. ## Definition of done - In a scratch repository, `git check-ignore -v` reports both names ignored at the root and two directories deep, and `id_ed25519_sk.pub` is not ignored. - A scratch image built with the canonical `.dockerignore` does not contain either name at the root or two directories deep, and does contain `id_ed25519_sk.pub`. - `make check` passes. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#81