Bring every copied template file to sneak/prompts next at dd4027b9 (closes #67)
check / check (push) Failing after 2s

REPO_POLICIES.md is the sneak/prompts next copy at commit
dd4027b907ef99cdc3187c215cc4d610b7a11efc. .gitignore and .dockerignore
are that commit's copies plus keyfunc's own /keyfunc entry: both now
ignore id_ecdsa_sk and id_ed25519_sk, the private key files ssh-keygen
writes for hardware-backed keys, and .dockerignore keeps out a
.git/config at any depth. The other copied files already matched that
commit. The template Dockerfile, scripts, Makefile and workflow have not
changed since keyfunc adapted them, and the new policy text asks nothing
new of keyfunc's Dockerfile: its gate phases install nothing and its
last stage already runs script/bootstrap.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:45:31 +00:00
parent e82c91d27c
commit f7bae92768
3 changed files with 58 additions and 15 deletions
+12 -3
View File
@@ -18,9 +18,16 @@
# does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there.
# Each submodule keeps a config with the same exposure in its git directory
# under .git/modules/, nested again for a submodule's own submodules.
.git/config
.git/modules/**/config
# under .git/modules/, nested again for a submodule's own submodules, or in
# its own .git directory when it keeps one.
# KNOWN GAP: a submodule whose name has a `config` segment (`config`,
# `deploy/config`, `config/lib`) loses its whole git directory, because
# `**/.git/modules/**/config` also matches that segment's directory
# under .git/modules/. Go's version stamping then fails the build;
# nothing leaks. Name such a submodule without that segment:
# `git submodule add --name`.
**/.git/config
**/.git/modules/**/config
# Agent scratch: one full checkout of the repo per in-flight agent.
# Anchored because it occurs once where agents run at the repo root.
@@ -44,7 +51,9 @@
**/[iI][dD]_[rR][sS][aA]
**/[iI][dD]_[dD][sS][aA]
**/[iI][dD]_[eE][cC][dD][sS][aA]
**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
**/[iI][dD]_[eE][dD]25519
**/[iI][dD]_[eE][dD]25519_[sS][kK]
# Dependencies: restored inside the image, never copied in.
**/node_modules