Cover more secret shapes in the canonical .gitignore (closes #38) #80

Merged
clawbot merged 2 commits from issue-38-gitignore-secrets into next 2026-10-03 17:39:41 +02:00
Collaborator

The canonical .gitignore matched only .env, .env.*, *.pem and *.key, so prod.env, .envrc, *.p12 and *.pfx bundles, and an SSH private key as ssh-keygen writes it (id_rsa, id_dsa, id_ecdsa, id_ed25519) were one git add from the repository, although REPO_POLICIES.md requires secrets to be in .gitignore. The secrets section now covers the same shapes as the canonical .dockerignore.

What the diff does not show:

  • These are written to .gitignore's rules, not copied from .dockerignore: unanchored, with no **/ prefix, because an unanchored .gitignore pattern already matches at every depth.
  • Git matches case-sensitively on Linux, so every name uses character ranges, as .dockerignore does.
  • !example.env and !sample.env keep those two templates trackable; the file's comment tells a repository to add its own negation for any other. Public keys such as id_rsa.pub stay trackable, since the key patterns match the whole file name.

Disclosures:

  • Judgement call: the plan said to keep the existing entries. Their coverage is kept, but the lines were rewritten with character ranges, which only widens them, and the bare .env line is gone because *.env covers it.
  • Judgement call: .env.example and .env.sample stay ignored, as they already were under .env.*.
  • Not in this PR: copying the file into consuming repos, which the re-vendor in #78 covers.

Closes #38

Model: opus-5-5

The canonical `.gitignore` matched only `.env`, `.env.*`, `*.pem` and `*.key`, so `prod.env`, `.envrc`, `*.p12` and `*.pfx` bundles, and an SSH private key as `ssh-keygen` writes it (`id_rsa`, `id_dsa`, `id_ecdsa`, `id_ed25519`) were one `git add` from the repository, although `REPO_POLICIES.md` requires secrets to be in `.gitignore`. The secrets section now covers the same shapes as the canonical `.dockerignore`. What the diff does not show: - These are written to `.gitignore`'s rules, not copied from `.dockerignore`: unanchored, with no `**/` prefix, because an unanchored `.gitignore` pattern already matches at every depth. - Git matches case-sensitively on Linux, so every name uses character ranges, as `.dockerignore` does. - `!example.env` and `!sample.env` keep those two templates trackable; the file's comment tells a repository to add its own negation for any other. Public keys such as `id_rsa.pub` stay trackable, since the key patterns match the whole file name. Disclosures: - Judgement call: the plan said to keep the existing entries. Their coverage is kept, but the lines were rewritten with character ranges, which only widens them, and the bare `.env` line is gone because `*.env` covers it. - Judgement call: `.env.example` and `.env.sample` stay ignored, as they already were under `.env.*`. - Not in this PR: copying the file into consuming repos, which the re-vendor in https://git.eeqj.de/sneak/prompts/issues/78 covers. Closes https://git.eeqj.de/sneak/prompts/issues/38 Model: opus-5-5
clawbot added the needs-review label 2026-10-03 15:54:17 +02:00
clawbot self-assigned this 2026-10-03 15:54:17 +02:00
clawbot added 1 commit 2026-10-03 15:54:18 +02:00
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`,
so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as
`ssh-keygen` writes it could all be committed. It now covers the same
shapes as `.dockerignore`, written to `.gitignore`'s own rules:
unanchored with no `**/` prefix, since an unanchored pattern already
matches at every depth, and case-folded with character ranges because
matching is case-sensitive on Linux. `example.env` and `sample.env` are
re-included so a committed template stays trackable.

Model: opus-5-5
Author
Collaborator
  • .gitignore, the environment-files comment: it says a *.env file committed on purpose, such as a template holding no real values, "is re-included by a negation", but the file re-includes only example.env and sample.env. Any other template (defaults.env, template.env, or the common .env.example) stays ignored. The instruction that a repository adds its own negation for such a file is only in the PR body, which a repository vendoring this file never sees. Acceptable: the comment names the two files it re-includes and tells a repository to add its own negation for any other committed template (for example !.env.example), the way the canonical .dockerignore comment does.

Model: opus-5-5

- `.gitignore`, the environment-files comment: it says a `*.env` file committed on purpose, such as a template holding no real values, "is re-included by a negation", but the file re-includes only `example.env` and `sample.env`. Any other template (`defaults.env`, `template.env`, or the common `.env.example`) stays ignored. The instruction that a repository adds its own negation for such a file is only in the PR body, which a repository vendoring this file never sees. Acceptable: the comment names the two files it re-includes and tells a repository to add its own negation for any other committed template (for example `!.env.example`), the way the canonical `.dockerignore` comment does. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-03 16:13:43 +02:00
clawbot added 1 commit 2026-10-03 16:55:16 +02:00
The comment said a committed template is re-included by a negation, but
the file re-includes only `example.env` and `sample.env`. It now names
those two and tells a repository to add its own negation after these
lines for any other template, for example `!.env.example`, as the
`.dockerignore` comment does.

Model: opus-5-5
Author
Collaborator

The environment-files comment in .gitignore now names the two templates it re-includes (example.env, sample.env) and tells a repository to add its own negation after those lines for any other committed template, for example !.env.example. The PR body now names the four key files covered.

Model: opus-5-5

The environment-files comment in `.gitignore` now names the two templates it re-includes (`example.env`, `sample.env`) and tells a repository to add its own negation after those lines for any other committed template, for example `!.env.example`. The PR body now names the four key files covered. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-03 16:55:22 +02:00
Author
Collaborator
  • Commit 96924d8 ("Name the re-included env templates in the .gitignore comment"): its subject does not end in (closes #N) for #38, and the PR title lacks it too, so the squashed commit can land on next without it. Acceptable: fold the rework into the first commit, so the branch is one commit whose subject ends in that suffix and whose body keeps its Model: line.

Model: opus-5-5

- Commit `96924d8` ("Name the re-included env templates in the .gitignore comment"): its subject does not end in ` (closes #N)` for https://git.eeqj.de/sneak/prompts/issues/38, and the PR title lacks it too, so the squashed commit can land on `next` without it. Acceptable: fold the rework into the first commit, so the branch is one commit whose subject ends in that suffix and whose body keeps its `Model:` line. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-03 17:10:05 +02:00
clawbot changed title from Cover more secret shapes in the canonical .gitignore to Cover more secret shapes in the canonical .gitignore (closes #38) 2026-10-03 17:11:00 +02:00
Author
Collaborator

Rework: the PR title now ends (closes #38). The PR lands as one squash commit whose subject is that title, so the branch's own commit subjects are left as they are.

Model: opus-5-5

Rework: the PR title now ends ` (closes #38)`. The PR lands as one squash commit whose subject is that title, so the branch's own commit subjects are left as they are. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-03 17:11:04 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot removed the needs-review label 2026-10-03 17:39:00 +02:00
clawbot merged commit 7ea5cdcdcd into next 2026-10-03 17:39:41 +02:00
clawbot deleted branch issue-38-gitignore-secrets 2026-10-03 17:39:41 +02:00
Sign in to join this conversation.