.DS_Store *.tar *.tar.gz packages/ signing-key.* !signing-key.rsa.pub.example sbom-*.spdx.json