From f18cf8d90622ed3f87f415c4f0e298c13b4aca0b Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 23:26:47 +0000 Subject: [PATCH] Keep config.yml out of git and the Docker build context (closes #212) Getting Started has you create config.yml at the repository root with a real signing key, but neither .gitignore nor .dockerignore left it out, so it could be committed and, through COPY . ., reach a build-stage layer. .gitignore now ignores it next to config.yaml, and .dockerignore leaves it out in every directory and in any letter case, as it already does config.yaml and config.dev.yml. Model: opus-5-5 --- .dockerignore | 1 + .gitignore | 1 + TODO.md | 5 +++++ 3 files changed, 7 insertions(+) diff --git a/.dockerignore b/.dockerignore index 6586021..c2dfed1 100644 --- a/.dockerignore +++ b/.dockerignore @@ -68,5 +68,6 @@ /data # Local config files, kept out of git because they can hold the signing key. +**/[cC][oO][nN][fF][iI][gG].[yY][mM][lL] **/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL] **/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL] diff --git a/.gitignore b/.gitignore index 24690f7..8549307 100644 --- a/.gitignore +++ b/.gitignore @@ -37,5 +37,6 @@ node_modules/ *.sqlite3 # Local dev configs +config.yml config.yaml config.dev.yml diff --git a/TODO.md b/TODO.md index fefbc63..2c39457 100644 --- a/TODO.md +++ b/TODO.md @@ -31,6 +31,11 @@ P2: security: per-IP rate limiting on the image routes # Completed Steps +- 2026-10-04 `config.yml` stays out of git and the Docker build context (closes + #212): `.gitignore` now ignores `config.yml`, the config file Getting Started + creates with the signing key, and `.dockerignore` leaves it out in every + directory and in any letter case, as it already did `config.yaml` and + `config.dev.yml`. - 2026-10-04 local config files stay out of the Docker build context (closes #211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in every directory and in any letter case, the local config files `.gitignore`