Found in review of #80. Both canonical ignore files list the SSH private key names id_rsa, id_dsa, id_ecdsa and id_ed25519, but not id_ecdsa_sk and id_ed25519_sk, the names ssh-keygen writes for keys backed by a hardware security key. Those files still hold key material, so a repository can commit or ship one.
Fix
Add both names to the secrets section of the canonical .gitignore (gitignore rules: unanchored, no **/, character ranges for case, as the other key names there) and of the canonical .dockerignore (its own rules: **/ prefix, character ranges). Public halves (*.pub) must stay trackable. One commit, both files, plus any canonical sentence that lists the key names (git grep -n -i 'id_ed25519' -- .).
Start only after #80 has merged to next, since it rewrites the same .gitignore section.
Definition of done
In a scratch repository, git check-ignore -v reports both names ignored at the root and two directories deep, and id_ed25519_sk.pub is not ignored.
A scratch image built with the canonical .dockerignore does not contain either name at the root or two directories deep, and does contain id_ed25519_sk.pub.
make check passes.
Model: opus-5-5
Found in review of https://git.eeqj.de/sneak/prompts/pulls/80. Both canonical ignore files list the SSH private key names `id_rsa`, `id_dsa`, `id_ecdsa` and `id_ed25519`, but not `id_ecdsa_sk` and `id_ed25519_sk`, the names `ssh-keygen` writes for keys backed by a hardware security key. Those files still hold key material, so a repository can commit or ship one.
## Fix
Add both names to the secrets section of the canonical `.gitignore` (gitignore rules: unanchored, no `**/`, character ranges for case, as the other key names there) and of the canonical `.dockerignore` (its own rules: `**/` prefix, character ranges). Public halves (`*.pub`) must stay trackable. One commit, both files, plus any canonical sentence that lists the key names (`git grep -n -i 'id_ed25519' -- .`).
Start only after https://git.eeqj.de/sneak/prompts/pulls/80 has merged to `next`, since it rewrites the same `.gitignore` section.
## Definition of done
- In a scratch repository, `git check-ignore -v` reports both names ignored at the root and two directories deep, and `id_ed25519_sk.pub` is not ignored.
- A scratch image built with the canonical `.dockerignore` does not contain either name at the root or two directories deep, and does contain `id_ed25519_sk.pub`.
- `make check` passes.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found in review of #80. Both canonical ignore files list the SSH private key names
id_rsa,id_dsa,id_ecdsaandid_ed25519, but notid_ecdsa_skandid_ed25519_sk, the namesssh-keygenwrites for keys backed by a hardware security key. Those files still hold key material, so a repository can commit or ship one.Fix
Add both names to the secrets section of the canonical
.gitignore(gitignore rules: unanchored, no**/, character ranges for case, as the other key names there) and of the canonical.dockerignore(its own rules:**/prefix, character ranges). Public halves (*.pub) must stay trackable. One commit, both files, plus any canonical sentence that lists the key names (git grep -n -i 'id_ed25519' -- .).Start only after #80 has merged to
next, since it rewrites the same.gitignoresection.Definition of done
git check-ignore -vreports both names ignored at the root and two directories deep, andid_ed25519_sk.pubis not ignored..dockerignoredoes not contain either name at the root or two directories deep, and does containid_ed25519_sk.pub.make checkpasses.Model: opus-5-5