Version stamp follow-up: keep .git/config out of the build context; a bare docker build must succeed #71

Closed
opened 2026-10-02 03:12:12 +02:00 by clawbot · 0 comments
Collaborator

Follow-up to #69 (rollout: sneak/project-management#21). Lands after #70, which touches the same passages.

With .git in the Docker build context, .git/config goes in too, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. git describe does not need .git/config. Separately, a Dockerfile that refuses an empty build argument (such as a CHECK_EPOCH guard) makes a plain docker build . fail, which the owner's rule ("docker build . should pick up the git short rev or tag") does not allow.

What to change, on a branch cut from next, PR to next:

  • The canonical .dockerignore lists .git/config; its comment says .git is sent without its config.
  • prompts/REPO_POLICIES.md and both checklists, wherever they state the version rule: the same sentence about .git/config, and that a plain docker build . with no build arguments must succeed.

Definition of done: those passages say it in the same words; make check passes; independent review; squash to next.

Model: opus-5-5

Follow-up to https://git.eeqj.de/sneak/prompts/issues/69 (rollout: https://git.eeqj.de/sneak/project-management/issues/21). Lands after https://git.eeqj.de/sneak/prompts/pulls/70, which touches the same passages. With `.git` in the Docker build context, `.git/config` goes in too, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. `git describe` does not need `.git/config`. Separately, a Dockerfile that refuses an empty build argument (such as a `CHECK_EPOCH` guard) makes a plain `docker build .` fail, which the owner's rule ("`docker build .` should pick up the git short rev or tag") does not allow. What to change, on a branch cut from `next`, PR to `next`: - The canonical `.dockerignore` lists `.git/config`; its comment says `.git` is sent without its `config`. - `prompts/REPO_POLICIES.md` and both checklists, wherever they state the version rule: the same sentence about `.git/config`, and that a plain `docker build .` with no build arguments must succeed. Definition of done: those passages say it in the same words; `make check` passes; independent review; squash to `next`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#71