From 717756df042d96e70da1a963262244670059b6c2 Mon Sep 17 00:00:00 2001 From: sneak Date: Sat, 3 Oct 2026 13:42:40 +0000 Subject: [PATCH 1/2] Cover more secret shapes in the canonical .gitignore (closes #38) The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`, so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as `ssh-keygen` writes it could all be committed. It now covers the same shapes as `.dockerignore`, written to `.gitignore`'s own rules: unanchored with no `**/` prefix, since an unanchored pattern already matches at every depth, and case-folded with character ranges because matching is case-sensitive on Linux. `example.env` and `sample.env` are re-included so a committed template stays trackable. Model: opus-5-5 --- .gitignore | 27 ++++++++++++++++++++++----- TODO.md | 5 +++++ 2 files changed, 27 insertions(+), 5 deletions(-) diff --git a/.gitignore b/.gitignore index 3558b76..deab9ab 100644 --- a/.gitignore +++ b/.gitignore @@ -20,8 +20,25 @@ Thumbs.db # Node node_modules/ -# Environment / secrets -.env -.env.* -*.pem -*.key +# Secrets. Unanchored like every entry above, so each matches at every +# depth. Matching is case-sensitive on Linux, so names use character +# ranges rather than a lowercase form that misses `Server.Key`. + +# Environment files. `*.env` covers bare `.env` and the `prod.env` +# convention. A file of this shape committed on purpose, such as a +# template holding no real values, is re-included by a negation. +*.[eE][nN][vV] +.[eE][nN][vV].* +.[eE][nN][vV][rR][cC] +!example.env +!sample.env + +# Private keys and the bundles carrying them. +*.[pP][eE][mM] +*.[kK][eE][yY] +*.[pP]12 +*.[pP][fF][xX] +[iI][dD]_[rR][sS][aA] +[iI][dD]_[dD][sS][aA] +[iI][dD]_[eE][cC][dD][sS][aA] +[iI][dD]_[eE][dD]25519 diff --git a/TODO.md b/TODO.md index 2a27314..f41f0b3 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,11 @@ fmt-check, and commit. # Completed Steps +- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on + secrets (issue 38): it now also ignores `prod.env`-style `*.env` files, + `.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to + `.gitignore`'s own rules (no `**/` prefix) and case-folded with character + ranges. `example.env` and `sample.env` stay trackable through negations. - 2026-10-02: The image version now comes from git inside the build (issues 69 and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical `.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a -- 2.54.0 From 96924d8dc9278408764572d5518ecbbafe0df711 Mon Sep 17 00:00:00 2001 From: sneak Date: Sat, 3 Oct 2026 14:25:39 +0000 Subject: [PATCH 2/2] Name the re-included env templates in the .gitignore comment The comment said a committed template is re-included by a negation, but the file re-includes only `example.env` and `sample.env`. It now names those two and tells a repository to add its own negation after these lines for any other template, for example `!.env.example`, as the `.dockerignore` comment does. Model: opus-5-5 --- .gitignore | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index deab9ab..4c335ba 100644 --- a/.gitignore +++ b/.gitignore @@ -25,8 +25,9 @@ node_modules/ # ranges rather than a lowercase form that misses `Server.Key`. # Environment files. `*.env` covers bare `.env` and the `prod.env` -# convention. A file of this shape committed on purpose, such as a -# template holding no real values, is re-included by a negation. +# convention. Only the templates `example.env` and `sample.env` are +# re-included below. A repository that commits any other template adds +# its own negation after these lines, for example `!.env.example`. *.[eE][nN][vV] .[eE][nN][vV].* .[eE][nN][vV][rR][cC] -- 2.54.0