diff --git a/.dockerignore b/.dockerignore index e532cdd..71f7fcc 100644 --- a/.dockerignore +++ b/.dockerignore @@ -16,6 +16,9 @@ coverage.out *.swo *~ +# Dependencies +node_modules + # macOS .DS_Store @@ -23,4 +26,4 @@ coverage.out .claude/ # Local settings -.claude/settings.local.json \ No newline at end of file +.claude/settings.local.json diff --git a/.gitignore b/.gitignore index fcdf079..41e8a67 100644 --- a/.gitignore +++ b/.gitignore @@ -1,12 +1,34 @@ +# OS .DS_Store -**/.DS_Store +Thumbs.db + +# Editors +*.swp +*.swo +*~ +*.bak +.idea/ +.vscode/ +*.sublime-* + +# Agent scratch (worktrees of this repo, created and destroyed by +# in-flight tooling). Unanchored: .gitignore patterns already match at +# every depth, so no prefix is wanted here. This is not a .dockerignore +# entry and must not be given a `**/` prefix on the way into one. +.claude/ + +# Node +node_modules/ + +# Environment / secrets +.env +.env.* +*.pem +*.key + +# This repo. /secret is the built binary, anchored so that it does not +# also match the internal/secret/ package directory. /secret *.log -cli.test -vault.test *.test settings.local.json - -# Stale files -.cursorrules -coverage.out diff --git a/TODO.md b/TODO.md index 413b1b2..99d609e 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,12 @@ Bring the repo into policy compliance in one commit: # Completed Steps +- 2026-10-04: `.gitignore` is the org's standard file, which ignores + `.env`, `.env.*`, `*.pem` and `*.key` and editor and OS files, plus + this repo's `/secret`, `*.log`, `*.test` and `settings.local.json` + (https://git.eeqj.de/sneak/secret/issues/40). `.dockerignore` also + leaves out `node_modules`; `.git` stays in the build context for the + version stamp. - 2026-10-04: `secret init` refuses when the default vault exists, and `secret vault create NAME` when `NAME` does, with "vault NAME already exists", before writing anything. The check is in `vault.CreateVault`,