Keep each submodule's git config out of the build context (closes #75)
check / check (push) Successful in 44s

The canonical .dockerignore kept out .git/config but not the config in
each submodule's git directory under .git/modules/, nested again for a
submodule's own submodules, which can hold the same credential. Add
.git/modules/**/config and say so in REPO_POLICIES.md and both
checklists.

The pattern stays under .git/modules/: .git/**/config would also drop a
branch or tag named config in the top-level repository, which
git describe may need.

Model: opus-5-5
This commit is contained in:
2026-10-04 02:54:48 +00:00
parent dcc0ba0b66
commit 13e713ba54
5 changed files with 67 additions and 54 deletions
+3
View File
@@ -17,7 +17,10 @@
# stage that compiles runs `git describe --tags --always` on .git, which
# does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there.
# Each submodule keeps a config with the same exposure in its git directory
# under .git/modules/, nested again for a submodule's own submodules.
.git/config
.git/modules/**/config
# Agent scratch: one full checkout of the repo per in-flight agent.
# Anchored because it occurs once where agents run at the repo root.