Harden .gitignore against key material and evidence outputs - #56
Merged
Merged
Conversation
Audit of the tracked set found nothing unneeded committed: all 316 files are source, tests, fixtures, docs, packaging or CI, and `git ls-files -i -c` is empty. The gap was forward protection -- several things this tool ingests or writes had no rule. - Key material: .env, *.keylog, sslkeys*.txt, *.pem, *.key. --tls-keylog and --ssh-keylog take NSS key logs, which tend to be left next to the capture being worked on. - Evidence outputs: *.wav (--voip-out decodes G.711 RTP to recovered call audio) and *.csv (--csv export). - *.mmdb -- GeoIP databases via PCAPPER_GEOIP_CITY_DB / _ASN_DB; large and MaxMind-licensed. - Compressed captures: *.pcap.gz, *.pcapng.gz, *.pcap.zst, *.pcapng.zst. - OS/editor cruft: Thumbs.db, desktop.ini, *.swp, *.swo, *~, *.bak, *.orig, *.rej. JSON is deliberately NOT blanket-ignored: the package ships *_mappings.json and *_opcodes.json as package-data. Verified after the change that the committed fixtures, golden files and JSON data files are still un-ignored, and that each new pattern fires. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0191oXC8gEZArceaJtGL2Lqf
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audit of the tracked set found nothing unneeded committed: all 316 files are source, tests, fixtures, docs, packaging or CI, and
git ls-files -i -cis empty. The gap was forward protection -- several things this tool ingests or writes had no rule.JSON is deliberately NOT blanket-ignored: the package ships *_mappings.json and *_opcodes.json as package-data. Verified after the change that the committed fixtures, golden files and JSON data files are still un-ignored, and that each new pattern fires.
Claude-Session: https://claude.ai/code/session_0191oXC8gEZArceaJtGL2Lqf