security: widen verifier (openssh/hyphenated-sk/ctx7sk/credential-assign/telegram/conn-string), fix GIT_WORKFLOW guidance
- BEGIN [A-Z0-9 ]*PRIVATE KEY now covers OPENSSH/RSA/EC variants - sk- patterns tolerate hyphens and prefixed families (ctx7sk-) - credential-assign catches PASSWORD=/token:/|API_KEY| tables (placeholder-aware) - telegram bot tokens + connection strings with embedded passwords - .obsidian/** third-party plugin code excluded from value scan (noise) - regression: all 12 files named in REVIEW-FOLLOWUP now flagged - GIT_WORKFLOW: drop git add . / Windows path, add verifier step, note force-push exception for the one-time history rewrite
This commit is contained in:
@@ -23,7 +23,7 @@ This prevents conflicts and ensures you're working with the latest version.
|
||||
### Morning (Session Start)
|
||||
|
||||
```bash
|
||||
cd D:\tmp\vault\my-vault
|
||||
cd ~/Documents/ob-vault/my-vault
|
||||
git pull
|
||||
git status # Check for any conflicts
|
||||
```
|
||||
@@ -45,9 +45,10 @@ git status # Periodically check changes
|
||||
|
||||
```bash
|
||||
git status # Review all changes
|
||||
git add . # Stage all changes
|
||||
git add <改动的具体路径> # 按路径暂存,别盲加
|
||||
node .scripts/verify-vault.mjs # 密钥扫描,退出码必须为 0
|
||||
git commit -m "vault backup: $(date +%Y-%m-%d\ %H:%M:%S)"
|
||||
git push # Sync to remote
|
||||
git push # Sync to remote(仅人工执行;agent 受 AGENTS.md 约束)
|
||||
```
|
||||
|
||||
**What this does**:
|
||||
@@ -104,7 +105,7 @@ Archive: Completed research project
|
||||
```bash
|
||||
git status # Check current state
|
||||
git pull # Sync from remote
|
||||
git add . # Stage all changes
|
||||
git add <具体路径> # Stage specific files
|
||||
git commit -m "message" # Commit with message
|
||||
git push # Sync to remote
|
||||
git log --oneline -10 # View recent commits
|
||||
@@ -193,7 +194,7 @@ Delete conflict markers (`<<<<<<<`, `=======`, `>>>>>>>`).
|
||||
**3. Stage and commit**
|
||||
|
||||
```bash
|
||||
git add .
|
||||
git add <已解决冲突的文件>
|
||||
git commit -m "Resolve merge conflicts"
|
||||
git push
|
||||
```
|
||||
@@ -375,7 +376,7 @@ git pull
|
||||
```bash
|
||||
git pull # May auto-merge
|
||||
# If conflicts, resolve manually
|
||||
git add .
|
||||
git add <已解决冲突的文件>
|
||||
git commit -m "Resolve merge conflicts"
|
||||
git push
|
||||
```
|
||||
@@ -427,8 +428,8 @@ git push
|
||||
|
||||
### DON'T ❌
|
||||
|
||||
- **Never force push** to main/master (`git push --force`)
|
||||
- **Don't commit secrets** (API keys, passwords)
|
||||
- **Never force push** to main/master (`git push --force`) —— 例外仅限一次性的历史清理维护窗口(清除已泄漏密钥,见 SECURITY_ROTATION_LOG)
|
||||
- **Don't commit secrets** (API keys, passwords) —— 提交前跑 `node .scripts/verify-vault.mjs`;agent 会话一律禁用 `git add .` 与 `git push`(见 AGENTS.md 权限表)
|
||||
- **Don't commit huge files** (videos > 50MB - use Git LFS)
|
||||
- **Don't edit history** of pushed commits (causes conflicts)
|
||||
- **Don't ignore conflicts** (resolve immediately)
|
||||
@@ -446,7 +447,7 @@ git pull
|
||||
# Work throughout day...
|
||||
|
||||
# Evening
|
||||
git add .
|
||||
git add <改动的具体路径>
|
||||
git commit -m "vault backup: $(date)"
|
||||
git push
|
||||
```
|
||||
@@ -460,7 +461,7 @@ git pull # Gets Desktop's changes
|
||||
# Work on laptop...
|
||||
|
||||
# Before sleep
|
||||
git add .
|
||||
git add <改动的具体路径>
|
||||
git commit -m "vault backup: $(date)"
|
||||
git push
|
||||
```
|
||||
@@ -486,7 +487,7 @@ git pull # Gets Laptop's changes
|
||||
# Daily workflow
|
||||
git pull # Start of session
|
||||
git status # Check changes
|
||||
git add . # Stage all
|
||||
git add <paths> # Stage specific files
|
||||
git commit -m "vault backup: $(date)" # Commit
|
||||
git push # End of session
|
||||
|
||||
@@ -534,5 +535,5 @@ git reset --hard origin/main
|
||||
|
||||
---
|
||||
|
||||
**Last Updated**: 2026-01-06
|
||||
**Last Updated**: 2026-09-26
|
||||
**See Also**: [[CLAUDE]], [[QUICK_REFERENCE]], [[TROUBLESHOOTING]]
|
||||
|
||||
Reference in New Issue
Block a user