.dockerignore patterns without a leading **/ match only at the root of the build context, so a nested .env, node_modules or private key still reached the context and, through COPY . ., a build-stage layer; there was no private key pattern at all. The file is now the standard .dockerignore from sneak/prompts, header comment included: every pattern that should match anywhere starts with **/, and environment files and private keys (.pem, .key, .p12, .pfx, the SSH key names) are matched in any letter case. It also brings in the standard OS and editor entries.
pixa's own differences, each with its reason in the file:
.git is still sent without .git/config, in place of the standard .git line, as decided in #166.
.gitignore, /bin and /data stay out. bin/ and data/ are written /bin and /data, as the standard file asks for a repo's own entries; they match the same paths as before.
Checked as the policy asks: files for every pattern planted at the root and two directories deep, a COPY . . image built with the old and the new file and listed, then removed.
Disclosures:
No test is committed; the check above is the one the plan asked for.
REPO_POLICIES.md in pixa is still the old copy (its re-vendoring is #196); this change follows the canonical file.
Not covered, outside this issue: the local configs .gitignore names, config.yaml and config.dev.yml, can hold the signing key and still reach the build context at the root.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/pixa/issues/205.
`.dockerignore` patterns without a leading `**/` match only at the root of the build context, so a nested `.env`, `node_modules` or private key still reached the context and, through `COPY . .`, a build-stage layer; there was no private key pattern at all. The file is now the standard `.dockerignore` from `sneak/prompts`, header comment included: every pattern that should match anywhere starts with `**/`, and environment files and private keys (`.pem`, `.key`, `.p12`, `.pfx`, the SSH key names) are matched in any letter case. It also brings in the standard OS and editor entries.
pixa's own differences, each with its reason in the file:
- `.git` is still sent without `.git/config`, in place of the standard `.git` line, as decided in https://git.eeqj.de/sneak/pixa/issues/166.
- `.gitignore`, `/bin` and `/data` stay out. `bin/` and `data/` are written `/bin` and `/data`, as the standard file asks for a repo's own entries; they match the same paths as before.
Checked as the policy asks: files for every pattern planted at the root and two directories deep, a `COPY . .` image built with the old and the new file and listed, then removed.
Disclosures:
- No test is committed; the check above is the one the plan asked for.
- `REPO_POLICIES.md` in pixa is still the old copy (its re-vendoring is https://git.eeqj.de/sneak/pixa/issues/196); this change follows the canonical file.
- Not covered, outside this issue: the local configs `.gitignore` names, `config.yaml` and `config.dev.yml`, can hold the signing key and still reach the build context at the root.
Model: opus-5-5
.dockerignore patterns without a leading **/ match only at the root of
the build context, so a nested .env or private key still reached it and,
through COPY . ., a build-stage layer. The file is now the standard one
from sneak/prompts: every pattern that should match anywhere has **/,
and private keys and environment files are matched in any letter case.
pixa keeps its own differences: .git is still sent without .git/config
in place of the standard .git line, which the version stamp needs, and
.gitignore, /bin and /data stay out.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #205.
.dockerignorepatterns without a leading**/match only at the root of the build context, so a nested.env,node_modulesor private key still reached the context and, throughCOPY . ., a build-stage layer; there was no private key pattern at all. The file is now the standard.dockerignorefromsneak/prompts, header comment included: every pattern that should match anywhere starts with**/, and environment files and private keys (.pem,.key,.p12,.pfx, the SSH key names) are matched in any letter case. It also brings in the standard OS and editor entries.pixa's own differences, each with its reason in the file:
.gitis still sent without.git/config, in place of the standard.gitline, as decided in #166..gitignore,/binand/datastay out.bin/anddata/are written/binand/data, as the standard file asks for a repo's own entries; they match the same paths as before.Checked as the policy asks: files for every pattern planted at the root and two directories deep, a
COPY . .image built with the old and the new file and listed, then removed.Disclosures:
REPO_POLICIES.mdin pixa is still the old copy (its re-vendoring is #196); this change follows the canonical file..gitignorenames,config.yamlandconfig.dev.yml, can hold the signing key and still reach the build context at the root.Model: opus-5-5
PASS at
101714f9f0588d993a54fb2257c7a20b3cb9705b, rebased ontonextatcca2e3f926d380baeb11244991c3fd220ef231ff.Model: opus-5-5
101714f9f0to4f1eef92ba