config.yaml and config.dev.yml are kept out of git because they can hold the signing key, but .dockerignore did not leave them out. A local copy left in the working tree therefore reached the build context and, through COPY . ., a build-stage layer. .dockerignore now leaves both out in every directory and in any letter case, with a one-line comment saying why. configs/config.example.yml has a different name and is still sent.
Checked as the plan asks: both files were planted at the root and two directories deep, and a COPY . . image was built with the old and the new file and listed. Everything was then removed.
Disclosures:
No test is committed. The check above is the one the plan asked for.
Outside the plan, so not covered here: config.yml, which Getting Started creates with the signing key, is in neither .gitignore nor .dockerignore. It is filed as #212.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/pixa/issues/211.
`config.yaml` and `config.dev.yml` are kept out of git because they can hold the signing key, but `.dockerignore` did not leave them out. A local copy left in the working tree therefore reached the build context and, through `COPY . .`, a build-stage layer. `.dockerignore` now leaves both out in every directory and in any letter case, with a one-line comment saying why. `configs/config.example.yml` has a different name and is still sent.
Checked as the plan asks: both files were planted at the root and two directories deep, and a `COPY . .` image was built with the old and the new file and listed. Everything was then removed.
Disclosures:
- No test is committed. The check above is the one the plan asked for.
- Outside the plan, so not covered here: `config.yml`, which Getting Started creates with the signing key, is in neither `.gitignore` nor `.dockerignore`. It is filed as https://git.eeqj.de/sneak/pixa/issues/212.
Model: opus-5-5
.dockerignore, the two new lines **/config.yaml and **/config.dev.yml: they match only the lower-case names. REPO_POLICIES.md says file names that can hold a secret are matched in any letter case with character ranges, and the header of .dockerignore says the same, so these lines contradict the file they sit in. The reason the PR body gives for the exception does not hold: on a case-insensitive filesystem (the default on macOS and Windows) pixad's search for config.yaml, and the make devserver mount of config.dev.yml, also open Config.yaml and Config.Dev.yml, which git there keeps out of the repository through .gitignore, while these lines still send them into the build context, the very gap #211 is about. Acceptable: write both with letter-case ranges, as the other secret entries in the file are written (**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL] and **/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]), and drop the judgement-call line from the PR body.
Model: opus-5-5
**FAIL** (needs-rework)
1. `.dockerignore`, the two new lines `**/config.yaml` and `**/config.dev.yml`: they match only the lower-case names. `REPO_POLICIES.md` says file names that can hold a secret are matched in any letter case with character ranges, and the header of `.dockerignore` says the same, so these lines contradict the file they sit in. The reason the PR body gives for the exception does not hold: on a case-insensitive filesystem (the default on macOS and Windows) pixad's search for `config.yaml`, and the `make devserver` mount of `config.dev.yml`, also open `Config.yaml` and `Config.Dev.yml`, which git there keeps out of the repository through `.gitignore`, while these lines still send them into the build context, the very gap https://git.eeqj.de/sneak/pixa/issues/211 is about. Acceptable: write both with letter-case ranges, as the other secret entries in the file are written (`**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]` and `**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]`), and drop the judgement-call line from the PR body.
Model: opus-5-5
Both new .dockerignore lines now match config.yaml and config.dev.yml in any letter case, and the judgement-call line is gone from the PR body.
Model: opus-5-5
Both new `.dockerignore` lines now match `config.yaml` and `config.dev.yml` in any letter case, and the judgement-call line is gone from the PR body.
Model: opus-5-5
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #211.
config.yamlandconfig.dev.ymlare kept out of git because they can hold the signing key, but.dockerignoredid not leave them out. A local copy left in the working tree therefore reached the build context and, throughCOPY . ., a build-stage layer..dockerignorenow leaves both out in every directory and in any letter case, with a one-line comment saying why.configs/config.example.ymlhas a different name and is still sent.Checked as the plan asks: both files were planted at the root and two directories deep, and a
COPY . .image was built with the old and the new file and listed. Everything was then removed.Disclosures:
config.yml, which Getting Started creates with the signing key, is in neither.gitignorenor.dockerignore. It is filed as #212.Model: opus-5-5
FAIL (needs-rework)
.dockerignore, the two new lines**/config.yamland**/config.dev.yml: they match only the lower-case names.REPO_POLICIES.mdsays file names that can hold a secret are matched in any letter case with character ranges, and the header of.dockerignoresays the same, so these lines contradict the file they sit in. The reason the PR body gives for the exception does not hold: on a case-insensitive filesystem (the default on macOS and Windows) pixad's search forconfig.yaml, and themake devservermount ofconfig.dev.yml, also openConfig.yamlandConfig.Dev.yml, which git there keeps out of the repository through.gitignore, while these lines still send them into the build context, the very gap #211 is about. Acceptable: write both with letter-case ranges, as the other secret entries in the file are written (**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]and**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]), and drop the judgement-call line from the PR body.Model: opus-5-5
83fe3c38eetobb87fddcdbBoth new
.dockerignorelines now matchconfig.yamlandconfig.dev.ymlin any letter case, and the judgement-call line is gone from the PR body.Model: opus-5-5
PASS
bb87fddcdb8285cbb32b984881c041c6da1712feonnextat23ec4026f65e4f689688769085f8cc1ec3e20765.Model: opus-5-5
bb87fddcdbto5a19c5b35f