Ignore hardware-backed SSH key files in the canonical ignore files (closes #81) #93

Merged
clawbot merged 1 commits from issue-81-sk-key-ignores into next 2026-10-04 09:14:53 +02:00
Collaborator

ssh-keygen names the private key file of a key backed by a hardware security key id_ecdsa_sk or id_ed25519_sk. The canonical .gitignore and .dockerignore listed only id_rsa, id_dsa, id_ecdsa and id_ed25519, so a repository could commit these files or copy them into an image.

Both names are added next to their plain counterparts, in each file's own style: unanchored in .gitignore, **/-prefixed in .dockerignore, and case-folded with character ranges in both. A pattern must match the whole file name, so id_ecdsa_sk.pub and id_ed25519_sk.pub stay trackable and still reach the build context.

No canonical sentence lists the key names one by one. REPO_POLICIES.md says "the extensionless SSH keys", which still holds, so it is unchanged.

Checks:

  • Scratch repository, git check-ignore -v: both names (and a mixed-case ID_Ed25519_SK) ignored at the root and two directories deep by the new lines; id_ed25519_sk.pub and id_ecdsa_sk.pub not ignored.
  • Same check with the .gitignore from next before this change: neither name ignored.
  • Scratch image built with the canonical .dockerignore and COPY . ., listed with find: neither name present at the root or two directories deep; both .pub files present.

Model: opus-5-5

`ssh-keygen` names the private key file of a key backed by a hardware security key `id_ecdsa_sk` or `id_ed25519_sk`. The canonical `.gitignore` and `.dockerignore` listed only `id_rsa`, `id_dsa`, `id_ecdsa` and `id_ed25519`, so a repository could commit these files or copy them into an image. Both names are added next to their plain counterparts, in each file's own style: unanchored in `.gitignore`, `**/`-prefixed in `.dockerignore`, and case-folded with character ranges in both. A pattern must match the whole file name, so `id_ecdsa_sk.pub` and `id_ed25519_sk.pub` stay trackable and still reach the build context. No canonical sentence lists the key names one by one. `REPO_POLICIES.md` says "the extensionless SSH keys", which still holds, so it is unchanged. Checks: - Scratch repository, `git check-ignore -v`: both names (and a mixed-case `ID_Ed25519_SK`) ignored at the root and two directories deep by the new lines; `id_ed25519_sk.pub` and `id_ecdsa_sk.pub` not ignored. - Same check with the `.gitignore` from `next` before this change: neither name ignored. - Scratch image built with the canonical `.dockerignore` and `COPY . .`, listed with `find`: neither name present at the root or two directories deep; both `.pub` files present. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 08:52:50 +02:00
clawbot self-assigned this 2026-10-04 08:52:50 +02:00
clawbot added 1 commit 2026-10-04 08:52:51 +02:00
ssh-keygen names the private key file of a key backed by a hardware
security key id_ecdsa_sk or id_ed25519_sk. Both canonical ignore files
listed only the four plain key names, so these could be committed or
copied into an image. Each file gets both names in its own pattern
style, case-folded with character ranges; the .pub halves still match
nothing and stay trackable.

Model: opus-5-5
Author
Collaborator

PASS: both hardware-backed key names are kept out of git and the build context at every depth in each file's own style, while their .pub halves stay in, which meets the definition of done of #81.

Model: opus-5-5

PASS: both hardware-backed key names are kept out of git and the build context at every depth in each file's own style, while their `.pub` halves stay in, which meets the definition of done of https://git.eeqj.de/sneak/prompts/issues/81. Model: opus-5-5
clawbot merged commit 567944f8d8 into next 2026-10-04 09:14:53 +02:00
clawbot deleted branch issue-81-sk-key-ignores 2026-10-04 09:14:53 +02:00
Sign in to join this conversation.