Add canonical policy dotfiles, harden both ignore files (closes #8)
REPO_POLICIES.md lists the files every repo must contain at minimum; four were missing here and .gitignore covered only Hugo's outputs. REPO_POLICIES.md is a byte-identical copy of the canonical file in the prompts repo, YAML front matter (title, last_modified) intact so it can be diffed against upstream as policy evolves. It is not clean under this repo's prettier settings, so the reformat is the next commit rather than churn mixed in here; the byte-identical copy is what landed. .editorconfig, .prettierrc and .prettierignore are the canonical contents. script/fmt and script/fmt-check keep passing --tab-width 4 --prose-wrap always on the command line: the duplication is deliberate so the scripts still work standalone when copied as a template, and the values agree, so adding .prettierrc changes nothing about what make fmt does. .gitignore keeps its three Hugo lines and gains the canonical OS/editor/node/secrets block plus .claude/. The secrets patterns are the point: a stray .env or private key can no longer be committed by a broad git add. .claude/ holds worktrees/, so without it a clean checkout with agent tooling present is not git status-clean. .dockerignore gains the same coverage but not the same syntax. It does not use .gitignore semantics: it matches with Go's filepath.Match rules extended with **, where * does not cross / and an unprefixed pattern is anchored at the context root. A bare *.key therefore excludes ./server.key and ships ./certs/server.key into the image, which is worse than an obviously incomplete file because it reads as complete. Every depth-independent pattern here carries an explicit **/ prefix; only the entries that are genuinely root-anchored by definition go bare - .git, Hugo's public and resources output directories, and .hugo_build.lock. The distinction is spelled out in a comment at the top of the file so the next edit does not quietly undo it. Excluding .claude/ also keeps entire additional checkouts of this repo out of the build context, which the Dockerfile's COPY . . would otherwise copy into the image. Verified by planting .env, server.key, deep.pem and node_modules two directories deep and building: with the patterns unprefixed all of them reach /src in the image, with **/ none do. Root-only testing does not exercise this and produces a false pass.
This commit is contained in:
@@ -1,4 +1,41 @@
|
||||
# NOTE: .dockerignore does NOT use .gitignore semantics. It matches with
|
||||
# Go's filepath.Match rules extended with `**`: `*` does not cross `/`,
|
||||
# and an unprefixed pattern is anchored at the context root. So a bare
|
||||
# `*.key` would exclude ./server.key but happily ship ./certs/server.key
|
||||
# into the image, and a bare `node_modules` would exclude only a
|
||||
# top-level one. Every depth-independent pattern below therefore carries
|
||||
# an explicit `**/` prefix. The only unprefixed entries are the ones that
|
||||
# are genuinely root-anchored: the repo's own .git, Hugo's output
|
||||
# directories, and Hugo's build lock, all of which exist at the context
|
||||
# root by definition.
|
||||
|
||||
# Repo and Hugo outputs (root-anchored on purpose)
|
||||
.git
|
||||
public
|
||||
resources
|
||||
.hugo_build.lock
|
||||
|
||||
# OS
|
||||
**/.DS_Store
|
||||
**/Thumbs.db
|
||||
|
||||
# Editors
|
||||
**/*.swp
|
||||
**/*.swo
|
||||
**/*~
|
||||
**/*.bak
|
||||
**/.idea
|
||||
**/.vscode
|
||||
**/*.sublime-*
|
||||
|
||||
# Node
|
||||
**/node_modules
|
||||
|
||||
# Environment / secrets
|
||||
**/.env
|
||||
**/.env.*
|
||||
**/*.pem
|
||||
**/*.key
|
||||
|
||||
# Agent tooling (holds worktrees/, i.e. entire additional checkouts)
|
||||
**/.claude
|
||||
|
||||
Reference in New Issue
Block a user