Ignore secrets and editor files in .gitignore (closes #40)
check / check (push) Failing after 3s

.gitignore had no secret patterns at all. It is now the org's standard
file, which ignores .env, .env.*, *.pem and *.key and editor and OS
files, plus this repo's /secret (anchored, so internal/secret/ is not
matched), *.log, *.test and settings.local.json. The stale
.cursorrules and coverage.out entries are gone. No tracked file
matches the new patterns.

.dockerignore also leaves out node_modules and ends with a newline.
.git stays in the build context because the build stamps the version
with git describe; .git/config stays excluded.

Model: opus-5-5
This commit was merged in pull request #85.
This commit is contained in:
2026-10-04 09:24:59 +02:00
parent fb4481b4f7
commit cba526d33f
3 changed files with 39 additions and 8 deletions
+4 -1
View File
@@ -16,6 +16,9 @@ coverage.out
*.swo *.swo
*~ *~
# Dependencies
node_modules
# macOS # macOS
.DS_Store .DS_Store
@@ -23,4 +26,4 @@ coverage.out
.claude/ .claude/
# Local settings # Local settings
.claude/settings.local.json .claude/settings.local.json
+29 -7
View File
@@ -1,12 +1,34 @@
# OS
.DS_Store .DS_Store
**/.DS_Store Thumbs.db
# Editors
*.swp
*.swo
*~
*.bak
.idea/
.vscode/
*.sublime-*
# Agent scratch (worktrees of this repo, created and destroyed by
# in-flight tooling). Unanchored: .gitignore patterns already match at
# every depth, so no prefix is wanted here. This is not a .dockerignore
# entry and must not be given a `**/` prefix on the way into one.
.claude/
# Node
node_modules/
# Environment / secrets
.env
.env.*
*.pem
*.key
# This repo. /secret is the built binary, anchored so that it does not
# also match the internal/secret/ package directory.
/secret /secret
*.log *.log
cli.test
vault.test
*.test *.test
settings.local.json settings.local.json
# Stale files
.cursorrules
coverage.out
+6
View File
@@ -25,6 +25,12 @@ Bring the repo into policy compliance in one commit:
# Completed Steps # Completed Steps
- 2026-10-04: `.gitignore` is the org's standard file, which ignores
`.env`, `.env.*`, `*.pem` and `*.key` and editor and OS files, plus
this repo's `/secret`, `*.log`, `*.test` and `settings.local.json`
(https://git.eeqj.de/sneak/secret/issues/40). `.dockerignore` also
leaves out `node_modules`; `.git` stays in the build context for the
version stamp.
- 2026-10-04: `secret init` refuses when the default vault exists, and - 2026-10-04: `secret init` refuses when the default vault exists, and
`secret vault create NAME` when `NAME` does, with "vault NAME already `secret vault create NAME` when `NAME` does, with "vault NAME already
exists", before writing anything. The check is in `vault.CreateVault`, exists", before writing anything. The check is in `vault.CreateVault`,