From 30d1e1758ccfc5b106ede70209f5aaf8d2f33580 Mon Sep 17 00:00:00 2001 From: sneak Date: Sun, 4 Oct 2026 06:50:49 +0000 Subject: [PATCH] Ignore hardware-backed SSH key files in the canonical ignore files (closes #81) ssh-keygen names the private key file of a key backed by a hardware security key id_ecdsa_sk or id_ed25519_sk. Both canonical ignore files listed only the four plain key names, so these could be committed or copied into an image. Each file gets both names in its own pattern style, case-folded with character ranges; the .pub halves still match nothing and stay trackable. Model: opus-5-5 --- .dockerignore | 2 ++ .gitignore | 2 ++ TODO.md | 4 ++++ 3 files changed, 8 insertions(+) diff --git a/.dockerignore b/.dockerignore index 351278b..d911b03 100644 --- a/.dockerignore +++ b/.dockerignore @@ -44,7 +44,9 @@ **/[iI][dD]_[rR][sS][aA] **/[iI][dD]_[dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA] +**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK] **/[iI][dD]_[eE][dD]25519 +**/[iI][dD]_[eE][dD]25519_[sS][kK] # Dependencies: restored inside the image, never copied in. **/node_modules diff --git a/.gitignore b/.gitignore index 4c335ba..534d4e2 100644 --- a/.gitignore +++ b/.gitignore @@ -42,4 +42,6 @@ node_modules/ [iI][dD]_[rR][sS][aA] [iI][dD]_[dD][sS][aA] [iI][dD]_[eE][cC][dD][sS][aA] +[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK] [iI][dD]_[eE][dD]25519 +[iI][dD]_[eE][dD]25519_[sS][kK] diff --git a/TODO.md b/TODO.md index 769cf3a..ad4785c 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,10 @@ fmt-check, and commit. # Completed Steps +- 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out + `id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes + for keys backed by a hardware security key (issue 81). Their `.pub` halves + stay trackable. - 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so yarn no longer prints "No license field" when `script/bootstrap` runs it inside the Docker phases (issue 76). That was the only yarn warning there. -- 2.54.0