Files
prompts/.gitignore
T
sneak 717756df04
check / check (push) Successful in 26s
Cover more secret shapes in the canonical .gitignore (closes #38)
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`,
so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as
`ssh-keygen` writes it could all be committed. It now covers the same
shapes as `.dockerignore`, written to `.gitignore`'s own rules:
unanchored with no `**/` prefix, since an unanchored pattern already
matches at every depth, and case-folded with character ranges because
matching is case-sensitive on Linux. `example.env` and `sample.env` are
re-included so a committed template stays trackable.

Model: opus-5-5
2026-10-03 13:42:40 +00:00

45 lines
1.0 KiB
Plaintext

# OS
.DS_Store
Thumbs.db
# Editors
*.swp
*.swo
*~
*.bak
.idea/
.vscode/
*.sublime-*
# Agent scratch (worktrees of this repo, created and destroyed by
# in-flight tooling). Unanchored: .gitignore patterns already match at
# every depth, so no prefix is wanted here. This is not a .dockerignore
# entry and must not be given a `**/` prefix on the way into one.
.claude/
# Node
node_modules/
# Secrets. Unanchored like every entry above, so each matches at every
# depth. Matching is case-sensitive on Linux, so names use character
# ranges rather than a lowercase form that misses `Server.Key`.
# Environment files. `*.env` covers bare `.env` and the `prod.env`
# convention. A file of this shape committed on purpose, such as a
# template holding no real values, is re-included by a negation.
*.[eE][nN][vV]
.[eE][nN][vV].*
.[eE][nN][vV][rR][cC]
!example.env
!sample.env
# Private keys and the bundles carrying them.
*.[pP][eE][mM]
*.[kK][eE][yY]
*.[pP]12
*.[pP][fF][xX]
[iI][dD]_[rR][sS][aA]
[iI][dD]_[dD][sS][aA]
[iI][dD]_[eE][cC][dD][sS][aA]
[iI][dD]_[eE][dD]25519