From 7a8ed5296dd0cae52ab0e534d0907bbd57264e17 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 06:14:09 +0000 Subject: [PATCH] Ignore secrets and editor files in .gitignore (closes #40) .gitignore had no secret patterns at all. It is now the org's standard file, which ignores .env, .env.*, *.pem and *.key and editor and OS files, plus this repo's /secret (anchored, so internal/secret/ is not matched), *.log, *.test and settings.local.json. The stale .cursorrules and coverage.out entries are gone. No tracked file matches the new patterns. .dockerignore also leaves out node_modules and ends with a newline. .git stays in the build context because the build stamps the version with git describe; .git/config stays excluded. Model: opus-5-5 --- .dockerignore | 5 ++++- .gitignore | 36 +++++++++++++++++++++++++++++------- TODO.md | 6 ++++++ 3 files changed, 39 insertions(+), 8 deletions(-) diff --git a/.dockerignore b/.dockerignore index e532cdd..71f7fcc 100644 --- a/.dockerignore +++ b/.dockerignore @@ -16,6 +16,9 @@ coverage.out *.swo *~ +# Dependencies +node_modules + # macOS .DS_Store @@ -23,4 +26,4 @@ coverage.out .claude/ # Local settings -.claude/settings.local.json \ No newline at end of file +.claude/settings.local.json diff --git a/.gitignore b/.gitignore index fcdf079..41e8a67 100644 --- a/.gitignore +++ b/.gitignore @@ -1,12 +1,34 @@ +# OS .DS_Store -**/.DS_Store +Thumbs.db + +# Editors +*.swp +*.swo +*~ +*.bak +.idea/ +.vscode/ +*.sublime-* + +# Agent scratch (worktrees of this repo, created and destroyed by +# in-flight tooling). Unanchored: .gitignore patterns already match at +# every depth, so no prefix is wanted here. This is not a .dockerignore +# entry and must not be given a `**/` prefix on the way into one. +.claude/ + +# Node +node_modules/ + +# Environment / secrets +.env +.env.* +*.pem +*.key + +# This repo. /secret is the built binary, anchored so that it does not +# also match the internal/secret/ package directory. /secret *.log -cli.test -vault.test *.test settings.local.json - -# Stale files -.cursorrules -coverage.out diff --git a/TODO.md b/TODO.md index 413b1b2..99d609e 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,12 @@ Bring the repo into policy compliance in one commit: # Completed Steps +- 2026-10-04: `.gitignore` is the org's standard file, which ignores + `.env`, `.env.*`, `*.pem` and `*.key` and editor and OS files, plus + this repo's `/secret`, `*.log`, `*.test` and `settings.local.json` + (https://git.eeqj.de/sneak/secret/issues/40). `.dockerignore` also + leaves out `node_modules`; `.git` stays in the build context for the + version stamp. - 2026-10-04: `secret init` refuses when the default vault exists, and `secret vault create NAME` when `NAME` does, with "vault NAME already exists", before writing anything. The check is in `vault.CreateVault`, -- 2.54.0