Keep secrets out of the Docker build context at every depth (closes #205)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
.dockerignore patterns without a leading **/ match only at the root of the build context, so a nested .env or private key still reached it and, through COPY . ., a build-stage layer. The file is now the standard one from sneak/prompts: every pattern that should match anywhere has **/, and private keys and environment files are matched in any letter case. pixa keeps its own differences: .git is still sent without .git/config in place of the standard .git line, which the version stamp needs, and .gitignore, /bin and /data stay out. Model: opus-5-5
This commit was merged in pull request #210.
This commit is contained in:
@@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
|
||||
file is now the standard one from `sneak/prompts`, whose patterns match in
|
||||
every directory and, for environment files and private keys, in any letter
|
||||
case, so a nested `.env` or `server.key` no longer reaches the build context.
|
||||
pixa still sends `.git` without `.git/config` in place of the standard file's
|
||||
`.git` line, and still leaves out `.gitignore`, `/bin` and `/data`.
|
||||
- 2026-10-04 `REPO_POLICIES.md` matches the canonical copy again (closes #196):
|
||||
it is replaced, unchanged, by `prompts/REPO_POLICIES.md` from `sneak/prompts`
|
||||
`main`. The rules it adds that pixa's tree breaks are filed:
|
||||
|
||||
Reference in New Issue
Block a user