Keep secrets out of the Docker build context at every depth (closes #205) #210

Merged
clawbot merged 1 commits from issue-205-dockerignore-every-depth into next 2026-10-05 00:07:37 +02:00
1 Commits
Author SHA1 Message Date
clawbot 4f1eef92ba Keep secrets out of the Docker build context at every depth (closes #205)
check / check (push) Failing after 4s
.dockerignore patterns without a leading **/ match only at the root of
the build context, so a nested .env or private key still reached it and,
through COPY . ., a build-stage layer. The file is now the standard one
from sneak/prompts: every pattern that should match anywhere has **/,
and private keys and environment files are matched in any letter case.

pixa keeps its own differences: .git is still sent without .git/config
in place of the standard .git line, which the version stamp needs, and
.gitignore, /bin and /data stay out.

Model: opus-5-5
2026-10-04 22:00:32 +00:00