check / check (push) Successful in 26s
The secrets section matched only `.env`, `.env.*`, `*.pem` and `*.key`, so `prod.env`, `.envrc`, `*.p12`, `*.pfx` and an SSH private key as `ssh-keygen` writes it could all be committed. It now covers the same shapes as `.dockerignore`, written to `.gitignore`'s own rules: unanchored with no `**/` prefix, since an unanchored pattern already matches at every depth, and case-folded with character ranges because matching is case-sensitive on Linux. `example.env` and `sample.env` are re-included so a committed template stays trackable. Model: opus-5-5
45 lines
1.0 KiB
Plaintext
45 lines
1.0 KiB
Plaintext
# OS
|
|
.DS_Store
|
|
Thumbs.db
|
|
|
|
# Editors
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
*.bak
|
|
.idea/
|
|
.vscode/
|
|
*.sublime-*
|
|
|
|
# Agent scratch (worktrees of this repo, created and destroyed by
|
|
# in-flight tooling). Unanchored: .gitignore patterns already match at
|
|
# every depth, so no prefix is wanted here. This is not a .dockerignore
|
|
# entry and must not be given a `**/` prefix on the way into one.
|
|
.claude/
|
|
|
|
# Node
|
|
node_modules/
|
|
|
|
# Secrets. Unanchored like every entry above, so each matches at every
|
|
# depth. Matching is case-sensitive on Linux, so names use character
|
|
# ranges rather than a lowercase form that misses `Server.Key`.
|
|
|
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
|
# convention. A file of this shape committed on purpose, such as a
|
|
# template holding no real values, is re-included by a negation.
|
|
*.[eE][nN][vV]
|
|
.[eE][nN][vV].*
|
|
.[eE][nN][vV][rR][cC]
|
|
!example.env
|
|
!sample.env
|
|
|
|
# Private keys and the bundles carrying them.
|
|
*.[pP][eE][mM]
|
|
*.[kK][eE][yY]
|
|
*.[pP]12
|
|
*.[pP][fF][xX]
|
|
[iI][dD]_[rR][sS][aA]
|
|
[iI][dD]_[dD][sS][aA]
|
|
[iI][dD]_[eE][cC][dD][sS][aA]
|
|
[iI][dD]_[eE][dD]25519
|