-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy path.gitignore
More file actions
142 lines (132 loc) · 5.32 KB
/
Copy path.gitignore
File metadata and controls
142 lines (132 loc) · 5.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# ==========================================================================================
# ALLOWLIST. This file ignores EVERYTHING and then names what belongs in the repository.
#
# Why inverted, and why this one is committed while the previous denylist was not: a denylist
# is a public inventory of the directories, tools and local layout a maintainer keeps out —
# free reconnaissance, and it grows every time someone adds a tool. An allowlist reveals only
# what is already visible to anyone who can see the tree, so it can be published without
# telling the world anything new.
#
# THREE RULES, in order of how much they cost when broken:
#
# 1. LAST MATCHING PATTERN WINS. The secrets section at the bottom is deliberately last, so a
# `!/scripts/**` further up cannot re-include a private key someone dropped in scripts/.
# Never append an un-ignore below that section.
# 2. `!*/` is load-bearing. Git does not descend into an ignored directory, so without it
# nothing below the top level could ever be re-included, no matter how many rules follow.
# 3. A NEW top-level file or directory is INVISIBLE until it is named here. That is the
# deliberate trade: a leak now requires an explicit mistake, while a legitimate addition
# requires one line. If `git status` does not show something you just created, this file
# is the reason — add it, do not reach for `git add -f`.
# ==========================================================================================
# Ignore everything…
*
# …but descend into directories, or rules 2 above cannot work.
!*/
# ------------------------------------------------------------------------------------------
# Source and resources
# ------------------------------------------------------------------------------------------
!/src/**
!/bin/**
!/gradle/**
!/config/**
!/scripts/**
!/docs/**
!/.github/**
!/.githooks/**
!/LICENSES/**
# ------------------------------------------------------------------------------------------
# Build, tooling and project configuration
# ------------------------------------------------------------------------------------------
!/build.gradle.kts
!/settings.gradle.kts
!/gradle.properties
!/gradlew
!/gradlew.bat
!/qodana.yaml
!/package.json
!/package-lock.json
!/vitest.config.js
!/eslint.config.mjs
!/tsconfig.json
!/.nvmrc
!/commitlint.config.mjs
!/.prettierrc.json
!/.prettierignore
!/.dockerignore
!/.gitattributes
!/.gitignore
# ------------------------------------------------------------------------------------------
# Documentation and governance
# ------------------------------------------------------------------------------------------
!/*.md
!/LICENSE
!/CODEOWNERS
# ------------------------------------------------------------------------------------------
# Re-ignored INSIDE the allowed trees. `!/src/**` re-includes everything under src/, including
# things that are generated there.
# ------------------------------------------------------------------------------------------
**/build/
**/node_modules/
# IDE state, including the sandbox project under src/uiTest/resources that `!/src/**` would
# otherwise re-include — it is a fixture the UI suite opens, so an IDE writes into it.
**/.idea/
*.class
# The same thing for the other toolchain: `!/scripts/**` re-includes the Python generators, and
# running one writes bytecode beside it.
*.pyc
**/__pycache__/
*.log
subprojects/
# ==========================================================================================
# SECRETS AND KEY MATERIAL — LAST, and it must stay last.
#
# `*` above already ignores these, so this section is belt-and-braces: it exists so that a
# future `!/some/tree/**` cannot silently re-include key material living inside that tree.
# A build artifact committed by accident is noise. A private key committed by accident is
# BURNED — forks, clones, forge caches and CI logs mean rewriting history does not un-leak it,
# the key has to be rotated. The concrete hazard: scripts/bootstrap-ci.sh asks where to save a
# generated JetBrains signing key, and answering "." puts private.pem in the working tree.
# ==========================================================================================
*.pem
*.key
*.p12
*.pfx
*.jks
*.keystore
*.der
*.pkcs8
chain.crt
# GPG / PGP
*.gpg
*.pgp
*.asc
secring.*
private.asc
passphrase
fingerprint
# Tokens and credentials
*.token
credentials.json
.npmrc
.netrc
auth.json
secrets.yml
secrets.yaml
.env
.env.*
# The ONE key file that must be committed: `docs/trust-chain.asc`, holding the PUBLIC halves of the
# two hardware CAs and of the CI signing key they certify. Without it nobody can verify a release,
# which is the whole point of signing one. Below the secrets block on purpose — last match wins, so
# this exception survives `*.asc` above.
#
# One named file rather than an un-ignored `docs/trust-*.asc`, and the difference matters: a glob
# here would silently commit whatever lands under that prefix, a PRIVATE block exported to the wrong
# filename included. A leak has to stay an explicit mistake.
!/docs/trust-chain.asc
PROJECTMAP.md
**/PROJECTMAP.md
# Anchored, because this holds whole checkouts: an assistant working in isolated worktrees puts them
# under .claude/worktrees/, and an unanchored pattern would also hide a real directory of that name
# somewhere in the tree. Committing it would commit a copy of the repository into the repository.
/.claude/