The comment said a committed template is re-included by a negation, but
the file re-includes only `example.env` and `sample.env`. It now names
those two and tells a repository to add its own negation after these
lines for any other template, for example `!.env.example`, as the
`.dockerignore` comment does.
Model: opus-5-5
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`,
so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as
`ssh-keygen` writes it could all be committed. It now covers the same
shapes as `.dockerignore`, written to `.gitignore`'s own rules:
unanchored with no `**/` prefix, since an unanchored pattern already
matches at every depth, and case-folded with character ranges because
matching is case-sensitive on Linux. `example.env` and `sample.env` are
re-included so a committed template stays trackable.
Model: opus-5-5