3 Commits
Author SHA1 Message Date
clawbot 3dcd4f6bb7 Fetch the tags in the CI checkout (closes #208)
check / check (push) Failing after 2s
The standard checkout action clones shallow and fetches no tags, so the
version the build takes from `git describe --tags --always` would be a
bare commit even on a tagged commit. The checkout step now sets
`fetch-depth: 0`, as REPO_POLICIES.md asks of a repo that takes its
version from the tags.

Model: opus-5-5
2026-10-04 23:59:32 +00:00
clawbot f77faf13de Keep config.yml out of git and the Docker build context (closes #212)
check / check (push) Failing after 2s
Getting Started has you create config.yml at the repository root with a
real signing key, but neither .gitignore nor .dockerignore left it out,
so it could be committed and, through COPY . ., reach a build-stage
layer. .gitignore now ignores it next to config.yaml, and .dockerignore
leaves it out in every directory and in any letter case, as it already
does config.yaml and config.dev.yml.

Model: opus-5-5
2026-10-05 01:58:32 +02:00
clawbot ae7c3f226d Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 2s
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.

Model: opus-5-5
2026-10-05 01:24:41 +02:00
4 changed files with 27 additions and 0 deletions
+5
View File
@@ -66,3 +66,8 @@
.gitignore
/bin
/data
# Local config files, kept out of git because they can hold the signing key.
**/[cC][oO][nN][fF][iI][gG].[yY][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]
+5
View File
@@ -6,5 +6,10 @@ jobs:
steps:
# actions/checkout v4.2.2, 2026-02-22
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
# The default clone is shallow and has no tags, so the
# version the build takes from `git describe` would be a
# bare commit; this fetches the whole history with its tags.
with:
fetch-depth: 0
- run: script/cibuild
- run: script/docker-smoke
+1
View File
@@ -37,5 +37,6 @@ node_modules/
*.sqlite3
# Local dev configs
config.yml
config.yaml
config.dev.yml
+16
View File
@@ -31,6 +31,22 @@ P2: security: per-IP rate limiting on the image routes
# Completed Steps
- 2026-10-04 the CI checkout fetches the tags (closes #208): the checkout step
in `.gitea/workflows/check.yml` sets `fetch-depth: 0`, as `REPO_POLICIES.md`
asks of a repo that takes its version from the tags, so a CI build of a tagged
commit stamps the tag from `git describe` instead of a bare commit.
- 2026-10-04 `config.yml` stays out of git and the Docker build context (closes
#212): `.gitignore` now ignores `config.yml`, the config file Getting Started
creates with the signing key, and `.dockerignore` leaves it out in every
directory and in any letter case, as it already did `config.yaml` and
`config.dev.yml`.
- 2026-10-04 local config files stay out of the Docker build context (closes
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
every directory and in any letter case, the local config files `.gitignore`
keeps out of git because they can hold the signing key.
`configs/config.example.yml` is still sent. `config.yml`, which Getting
Started creates, is in neither file:
https://git.eeqj.de/sneak/pixa/issues/212.
- 2026-10-04 `cmd/pixad/main.go` is one call into `internal/` (closes #206):
what it did (the command line and its `--config` flag, setting
`PIXA_CONFIG_PATH`, ignoring `SIGPIPE`, starting the fx app) is now `Run` in