From 32a4a82cfc1929ba02785275c7c9f5b31d721410 Mon Sep 17 00:00:00 2001 From: SackOfHacks Date: Sun, 13 Sep 2026 11:55:43 -0600 Subject: [PATCH] Harden .gitignore against key material and evidence outputs Audit of the tracked set found nothing unneeded committed: all 316 files are source, tests, fixtures, docs, packaging or CI, and `git ls-files -i -c` is empty. The gap was forward protection -- several things this tool ingests or writes had no rule. - Key material: .env, *.keylog, sslkeys*.txt, *.pem, *.key. --tls-keylog and --ssh-keylog take NSS key logs, which tend to be left next to the capture being worked on. - Evidence outputs: *.wav (--voip-out decodes G.711 RTP to recovered call audio) and *.csv (--csv export). - *.mmdb -- GeoIP databases via PCAPPER_GEOIP_CITY_DB / _ASN_DB; large and MaxMind-licensed. - Compressed captures: *.pcap.gz, *.pcapng.gz, *.pcap.zst, *.pcapng.zst. - OS/editor cruft: Thumbs.db, desktop.ini, *.swp, *.swo, *~, *.bak, *.orig, *.rej. JSON is deliberately NOT blanket-ignored: the package ships *_mappings.json and *_opcodes.json as package-data. Verified after the change that the committed fixtures, golden files and JSON data files are still un-ignored, and that each new pattern fires. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_0191oXC8gEZArceaJtGL2Lqf --- .gitignore | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/.gitignore b/.gitignore index 7212294..3b65d4e 100644 --- a/.gitignore +++ b/.gitignore @@ -28,9 +28,17 @@ htmlcov/ # Editor / OS .DS_Store +Thumbs.db +desktop.ini .claude/ .idea/ .vscode/ +*.swp +*.swo +*~ +*.bak +*.orig +*.rej # Logs *.log @@ -42,6 +50,10 @@ htmlcov/ *.pcap *.pcapng *.cap +*.pcap.gz +*.pcapng.gz +*.pcap.zst +*.pcapng.zst files/ # ...except the synthetic test fixtures, which are committed so the suite runs @@ -58,6 +70,27 @@ case-*/ *.sqlite3 *.db pcapper.toml +# --voip-out decodes G.711 RTP to WAV; recovered call audio is evidence. +*.wav +# --csv export. No CSV is committed, so a blanket rule is safe here; JSON is +# deliberately NOT blanket-ignored because the package ships *_mappings.json +# and *_opcodes.json data files (see [tool.setuptools.package-data]). +*.csv + +# Key material and secrets. --tls-keylog / --ssh-keylog take NSS key logs, and +# decryption workflows tend to leave keys next to the capture being worked on. +# Add a fixture with `git add -f` if the suite ever needs a committed cert. +.env +.env.* +*.keylog +*keylog*.txt +sslkeys*.txt +*.pem +*.key + +# GeoIP databases (PCAPPER_GEOIP_CITY_DB / PCAPPER_GEOIP_ASN_DB) — large, +# licensed, and redistributed by MaxMind, never by this repo. +*.mmdb # Jupyter .ipynb_checkpoints/