Cover more secret shapes in the canonical .gitignore (closes #38) #80

Merged
clawbot merged 2 commits from issue-38-gitignore-secrets into next 2026-10-03 17:39:41 +02:00
2 Commits
Author SHA1 Message Date
sneak 96924d8dc9 Name the re-included env templates in the .gitignore comment
check / check (push) Successful in 28s
The comment said a committed template is re-included by a negation, but
the file re-includes only `example.env` and `sample.env`. It now names
those two and tells a repository to add its own negation after these
lines for any other template, for example `!.env.example`, as the
`.dockerignore` comment does.

Model: opus-5-5
2026-10-03 14:25:39 +00:00
sneak 717756df04 Cover more secret shapes in the canonical .gitignore (closes #38)
check / check (push) Successful in 26s
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`,
so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as
`ssh-keygen` writes it could all be committed. It now covers the same
shapes as `.dockerignore`, written to `.gitignore`'s own rules:
unanchored with no `**/` prefix, since an unanchored pattern already
matches at every depth, and case-folded with character ranges because
matching is case-sensitive on Linux. `example.env` and `sample.env` are
re-included so a committed template stays trackable.

Model: opus-5-5
2026-10-03 13:42:40 +00:00