From 4a7bdf8f618c60f13a34c050bbe2bbbd02dc3198 Mon Sep 17 00:00:00 2001 From: clawbot Date: Sun, 9 Aug 2026 04:59:24 +0000 Subject: [PATCH] chore: root .editorconfig and hardened .gitignore (closes #15) Three root-level dotfiles diverged from the org models. Two are fixed here; the third is deferred for a reason spelled out below. Move backend/.editorconfig to the repo root. The file is byte-identical to the org model, so this is a pure relocation with no content change. It carries root = true, which one level down was actively harmful: it stopped editors walking further up, leaving the entire frontend (src/, index.html, vite.config.js, nginx.conf, script/) with no indentation settings at all. At the root the same file covers the whole tree, backend included, so the subdirectory copy is redundant. Replace .gitignore with the org model verbatim, then re-append the two repo-specific entries the model does not carry: dist/ (Vite output) and *.log. This adds the OS entry Thumbs.db, the entire Editors section (*.swp, *.swo, *~, *.bak, .idea/, .vscode/, *.sublime-*), and the Environment / secrets section (.env, .env.*, *.pem, *.key). The secrets section is the substantive part. The backend loads .env via godotenv and only backend/.gitignore ignored it, so a .env at the repo root was untracked but unignored -- one git add -A away from being committed. Policy allows no exceptions there. Not done here: excluding .git from .dockerignore. Both images read git metadata at build time. Dockerfile.backend has an explicit COPY .git /repo/.git feeding git describe in backend/Makefile, and the frontend Dockerfile's make check runs vite, whose config calls git rev-parse at config-eval time. Ignoring .git breaks both builds outright rather than degrading them, and decoupling them from git metadata belongs to the Dockerfile rework in #17. Deferred deliberately, not overlooked; tracked separately so it is not lost. No tracked file becomes ignored by the new patterns: git ls-files differs only by the .editorconfig relocation, and check-ignore over the full tracked set matches nothing. --- backend/.editorconfig => .editorconfig | 0 .gitignore | 27 ++++++++++++++++++++++++-- TODO.md | 7 +++++++ 3 files changed, 32 insertions(+), 2 deletions(-) rename backend/.editorconfig => .editorconfig (100%) diff --git a/backend/.editorconfig b/.editorconfig similarity index 100% rename from backend/.editorconfig rename to .editorconfig diff --git a/.gitignore b/.gitignore index 9451024..ee4128a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,27 @@ -node_modules/ -dist/ +# OS .DS_Store +Thumbs.db + +# Editors +*.swp +*.swo +*~ +*.bak +.idea/ +.vscode/ +*.sublime-* + +# Node +node_modules/ + +# Environment / secrets +.env +.env.* +*.pem +*.key + +# Build output +dist/ + +# Logs *.log diff --git a/TODO.md b/TODO.md index 587c805..2545dc2 100644 --- a/TODO.md +++ b/TODO.md @@ -22,6 +22,13 @@ files, so merging it also closes most compliance gaps. # Completed Steps +- 2026-08-09: dotfile compliance — lifted `backend/.editorconfig` to the repo + root so `root = true` covers the frontend too, and replaced `.gitignore` with + the org model (OS, editor, node, and environment/secrets sections) plus this + repo's `dist/` and `*.log`. `.env`, `.env.*`, `*.pem`, and `*.key` are now + ignored repo-wide, not just under `backend/`. Excluding `.git` from + `.dockerignore` stays deferred: both images read git metadata at build time + (`COPY .git` in `Dockerfile.backend`, `git rev-parse` in `vite.config.js`) - 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile shims, README Entrypoints section - 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow