Files
langchain/.gitignore
Mason Daugherty 447e45604f chore(infra): expand credential coverage in root .gitignore (#39147)
The root `.gitignore` covers `.env` files, `*.pem`/`*.key`/`*.crt`, and
`credentials.json`, but a number of common local credential files are
still stageable and easy to commit by accident — especially SSH private
keys, which usually have no extension, so the existing `*.key` pattern
never matches `id_rsa` or `id_ed25519`.

This adds ignores, all within the existing `# Environments` section,
for:

- **SSH private keys** — `id_rsa` / `id_dsa` / `id_ecdsa` / `id_ed25519`
and their `*_rsa` / `*_dsa` / `*_ecdsa` / `*_ed25519` counterparts. A
`!*.pub` negation keeps public keys (e.g. `id_rsa.pub`,
`deploy_ed25519.pub`) committable, since those are not secrets and are
sometimes checked in deliberately.
- **Keystores** — `*.p12`, `*.pfx`, `*.jks`.
- **Tokens, cookie jars, and git credential stores** — `token.json`,
`Cookies`, `Cookies.db`, `cookies.sqlite`, `cookies.txt`,
`.git-credentials`.

No source files are touched; this only narrows what `git add` will
stage.

## Verification

`git check-ignore` is authoritative here (grepping the file is not,
since patterns can come from multiple files).

Newly ignored (all `IGNORED`):

```text
IGNORED      id_rsa
IGNORED      id_dsa
IGNORED      id_ecdsa
IGNORED      id_ed25519
IGNORED      mykey_rsa
IGNORED      deploy_ed25519
IGNORED      x.p12
IGNORED      x.pfx
IGNORED      x.jks
IGNORED      token.json
IGNORED      Cookies
IGNORED      cookies.sqlite
IGNORED      cookies.txt
IGNORED      .git-credentials
```

Deliberately still committable (all NOT ignored):

```text
ok  id_rsa.pub
ok  deploy_ed25519.pub
ok  .env.example
```

The `!*.pub` negation is placed after the key patterns so it is not
re-matched, and `.env.example`'s existing `!.env.example` negation is
earlier in the file than every new pattern, so neither is re-ignored.
Finally, `git ls-files | git check-ignore --stdin` prints nothing,
confirming no already-tracked file is newly shadowed.
2026-07-30 11:27:08 -04:00

198 lines
2.6 KiB
Plaintext

.vs/
.claude/
.idea/
#Emacs backup
*~
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class
# C extensions
*.so
# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
pip-wheel-metadata/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST
# Google GitHub Actions credentials files created by:
# https://github.com/google-github-actions/auth
#
# That action recommends adding this gitignore to prevent accidentally committing keys.
gha-creds-*.json
# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec
# Installer logs
pip-log.txt
pip-delete-this-directory.txt
# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
.codspeed/
# Translations
*.mo
*.pot
# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal
# Flask stuff:
instance/
.webassets-cache
# Scrapy stuff:
.scrapy
# PyBuilder
target/
# Jupyter Notebook
.ipynb_checkpoints
notebooks/
# IPython
profile_default/
ipython_config.py
# pyenv
.python-version
# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock
# PEP 582; used by e.g. github.com/David-OConnor/pyflow
__pypackages__/
# Celery stuff
celerybeat-schedule
celerybeat.pid
# SageMath parsed files
*.sage.py
# Environments
.env
.env.*
!.env.example
.envrc
*.pem
*.key
*.crt
credentials.json
# SSH private keys (no file extension, so *.key never matches them)
id_rsa
id_dsa
id_ecdsa
id_ed25519
*_rsa
*_dsa
*_ecdsa
*_ed25519
!*.pub
# Keystores
*.p12
*.pfx
*.jks
# Tokens, cookie jars, and git credential stores
token.json
Cookies
Cookies.db
cookies.sqlite
cookies.txt
.git-credentials
.venv*
venv*
env/
ENV/
env.bak/
# Spyder project settings
.spyderproject
.spyproject
# Rope project settings
.ropeproject
# mkdocs documentation
/site
# mypy
.mypy_cache/
.mypy_cache_test/
.dmypy.json
dmypy.json
# Pyre type checker
.pyre/
# macOS display setting files
.DS_Store
# Wandb directory
wandb/
# asdf tool versions
.tool-versions
/.ruff_cache/
*.pkl
*.bin
# integration test artifacts
data_map*
\[('_type', 'fake'), ('stop', None)]
# Replit files
*replit*
node_modules
prof
virtualenv/
scratch/
.langgraph_api/