Canonical .dockerignore keeps out .git/config but not a submodule's config #75

Closed
opened 2026-10-03 14:19:03 +02:00 by clawbot · 1 comment
Collaborator

Item 3 of #72, split out so it can land while the pinning question there waits on the owner.

The canonical .dockerignore on next sends .git into the build context without .git/config, because that file can hold a credential (a password in a remote URL, or the token a CI checkout stores there). A repository with submodules keeps each submodule's git directory under .git/modules/<name>/, nested again for submodules of submodules, and each of those has its own config with the same exposure. None of them is excluded.

Fix

Add the pattern(s) that keep out every config under .git/modules/, at any nesting depth, written to .dockerignore's own matching rules (moby/patternmatcher, explained at the top of the file). Extend the comment above .git/config to cover it in one sentence. Make the same change wherever canonical text describes what .dockerignore keeps out of .git (prompts/REPO_POLICIES.md and both checklists; git grep -n '\.git/config' -- prompts/).

Do not exclude anything git describe needs: it must still produce the right version in the build.

Definition of done

  • Verified by enumerating the image, not by reading the file: in a scratch repository with a submodule that itself has a submodule, build an image that copies the context, and list what arrived. No config under .git/ reaches the image at any depth; git describe --tags --always inside the build still prints the expected version; a control build without the new pattern shows the nested configs arriving.
  • make check passes.

Model: opus-5-5

Item 3 of https://git.eeqj.de/sneak/prompts/issues/72, split out so it can land while the pinning question there waits on the owner. The canonical `.dockerignore` on `next` sends `.git` into the build context without `.git/config`, because that file can hold a credential (a password in a remote URL, or the token a CI checkout stores there). A repository with submodules keeps each submodule's git directory under `.git/modules/<name>/`, nested again for submodules of submodules, and each of those has its own `config` with the same exposure. None of them is excluded. ## Fix Add the pattern(s) that keep out every `config` under `.git/modules/`, at any nesting depth, written to `.dockerignore`'s own matching rules (moby/patternmatcher, explained at the top of the file). Extend the comment above `.git/config` to cover it in one sentence. Make the same change wherever canonical text describes what `.dockerignore` keeps out of `.git` (`prompts/REPO_POLICIES.md` and both checklists; `git grep -n '\.git/config' -- prompts/`). Do not exclude anything `git describe` needs: it must still produce the right version in the build. ## Definition of done - Verified by enumerating the image, not by reading the file: in a scratch repository with a submodule that itself has a submodule, build an image that copies the context, and list what arrived. No `config` under `.git/` reaches the image at any depth; `git describe --tags --always` inside the build still prints the expected version; a control build without the new pattern shows the nested configs arriving. - `make check` passes. Model: opus-5-5
Author
Collaborator

Implemented in #85: the canonical .dockerignore now also keeps out .git/modules/**/config, and the policy text and both checklists say so. One known gap, a submodule named config, is stated on the PR.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/prompts/pulls/85: the canonical `.dockerignore` now also keeps out `.git/modules/**/config`, and the policy text and both checklists say so. One known gap, a submodule named `config`, is stated on the PR. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#75