diff --git a/.gitignore b/.gitignore index 3558b76..4c335ba 100644 --- a/.gitignore +++ b/.gitignore @@ -20,8 +20,26 @@ Thumbs.db # Node node_modules/ -# Environment / secrets -.env -.env.* -*.pem -*.key +# Secrets. Unanchored like every entry above, so each matches at every +# depth. Matching is case-sensitive on Linux, so names use character +# ranges rather than a lowercase form that misses `Server.Key`. + +# Environment files. `*.env` covers bare `.env` and the `prod.env` +# convention. Only the templates `example.env` and `sample.env` are +# re-included below. A repository that commits any other template adds +# its own negation after these lines, for example `!.env.example`. +*.[eE][nN][vV] +.[eE][nN][vV].* +.[eE][nN][vV][rR][cC] +!example.env +!sample.env + +# Private keys and the bundles carrying them. +*.[pP][eE][mM] +*.[kK][eE][yY] +*.[pP]12 +*.[pP][fF][xX] +[iI][dD]_[rR][sS][aA] +[iI][dD]_[dD][sS][aA] +[iI][dD]_[eE][cC][dD][sS][aA] +[iI][dD]_[eE][dD]25519 diff --git a/TODO.md b/TODO.md index 2a27314..f41f0b3 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,11 @@ fmt-check, and commit. # Completed Steps +- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on + secrets (issue 38): it now also ignores `prod.env`-style `*.env` files, + `.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to + `.gitignore`'s own rules (no `**/` prefix) and case-folded with character + ranges. `example.env` and `sample.env` stay trackable through negations. - 2026-10-02: The image version now comes from git inside the build (issues 69 and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical `.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a