Keep each submodule's git config out of the build context (closes #75)
check / check (push) Successful in 44s
check / check (push) Successful in 44s
The canonical .dockerignore kept out .git/config but not the config in each submodule's git directory under .git/modules/, nested again for a submodule's own submodules, which can hold the same credential. Add .git/modules/**/config and say so in REPO_POLICIES.md and both checklists. The pattern stays under .git/modules/: .git/**/config would also drop a branch or tag named config in the top-level repository, which git describe may need. Model: opus-5-5
This commit is contained in:
@@ -21,6 +21,12 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: The canonical `.dockerignore` now also keeps out each submodule's
|
||||
`config` (issue 75). A submodule's git directory lives under `.git/modules/`,
|
||||
nested again for its own submodules, and its `config` can hold a credential
|
||||
just like `.git/config`. The pattern `.git/modules/**/config` covers every
|
||||
depth and leaves the top-level `.git` that `git describe` reads untouched.
|
||||
`REPO_POLICIES.md` and both checklists say so in the same words.
|
||||
- 2026-10-03: Fixed two defects in the canonical Go `Dockerfile` example (issue
|
||||
73). The test phase now uses the Debian Go image, since `-race` needs cgo and
|
||||
the alpine image has no C compiler, so the phase failed before running a test.
|
||||
|
||||
Reference in New Issue
Block a user