With .git in the Docker build context, .git/config goes in too, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. git describe does not need .git/config. Separately, a Dockerfile that refuses an empty build argument (such as a CHECK_EPOCH guard) makes a plain docker build . fail, which the owner's rule ("docker build . should pick up the git short rev or tag") does not allow.
What to change, on a branch cut from next, PR to next:
The canonical .dockerignore lists .git/config; its comment says .git is sent without its config.
prompts/REPO_POLICIES.md and both checklists, wherever they state the version rule: the same sentence about .git/config, and that a plain docker build . with no build arguments must succeed.
Definition of done: those passages say it in the same words; make check passes; independent review; squash to next.
Model: opus-5-5
Follow-up to https://git.eeqj.de/sneak/prompts/issues/69 (rollout: https://git.eeqj.de/sneak/project-management/issues/21). Lands after https://git.eeqj.de/sneak/prompts/pulls/70, which touches the same passages.
With `.git` in the Docker build context, `.git/config` goes in too, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. `git describe` does not need `.git/config`. Separately, a Dockerfile that refuses an empty build argument (such as a `CHECK_EPOCH` guard) makes a plain `docker build .` fail, which the owner's rule ("`docker build .` should pick up the git short rev or tag") does not allow.
What to change, on a branch cut from `next`, PR to `next`:
- The canonical `.dockerignore` lists `.git/config`; its comment says `.git` is sent without its `config`.
- `prompts/REPO_POLICIES.md` and both checklists, wherever they state the version rule: the same sentence about `.git/config`, and that a plain `docker build .` with no build arguments must succeed.
Definition of done: those passages say it in the same words; `make check` passes; independent review; squash to `next`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Follow-up to #69 (rollout: sneak/project-management#21). Lands after #70, which touches the same passages.
With
.gitin the Docker build context,.git/configgoes in too, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host.git describedoes not need.git/config. Separately, a Dockerfile that refuses an empty build argument (such as aCHECK_EPOCHguard) makes a plaindocker build .fail, which the owner's rule ("docker build .should pick up the git short rev or tag") does not allow.What to change, on a branch cut from
next, PR tonext:.dockerignorelists.git/config; its comment says.gitis sent without itsconfig.prompts/REPO_POLICIES.mdand both checklists, wherever they state the version rule: the same sentence about.git/config, and that a plaindocker build .with no build arguments must succeed.Definition of done: those passages say it in the same words;
make checkpasses; independent review; squash tonext.Model: opus-5-5