The canonical .dockerignore kept out .git/config but not the config in each submodule's git directory under .git/modules/ (nested again for a submodule's own submodules), which can hold the same credential. It now also lists .git/modules/**/config, with one sentence added to the comment above. prompts/REPO_POLICIES.md and both checklists say so in the same words.
The pattern stays under .git/modules/ on purpose: .git/**/config would also drop a branch or tag named config in the top-level repository, which git describe may need.
Verification, on a scratch repository whose submodule has its own submodule, with a stand-in credential in each submodule's config, built with COPY . . and the image enumerated:
New pattern: no config under .git/ at any depth; the credential is nowhere in the image.
Same build: git describe --tags --always printed the host's version, and Go's version stamping, which runs git status into the submodules, still worked.
Control with the .dockerignore from next: both nested submodule configs arrived, credential included.
Disclosures:
Known gap, seen in the scratch repository: a submodule named config matches the pattern as a directory, so its whole git directory stays out and Go's version stamping fails the build; git describe is unaffected. A narrower pattern needs negations that let deeper configs back in, so I kept the plain one. The gap is stated here, not in the file, because the issue limits the comment to one sentence.
Judgement call: last_modified set to 2026-10-04 in the three policy documents.
Model: opus-5-5
Item 3 of https://git.eeqj.de/sneak/prompts/issues/72.
The canonical `.dockerignore` kept out `.git/config` but not the `config` in each submodule's git directory under `.git/modules/` (nested again for a submodule's own submodules), which can hold the same credential. It now also lists `.git/modules/**/config`, with one sentence added to the comment above. `prompts/REPO_POLICIES.md` and both checklists say so in the same words.
The pattern stays under `.git/modules/` on purpose: `.git/**/config` would also drop a branch or tag named `config` in the top-level repository, which `git describe` may need.
Verification, on a scratch repository whose submodule has its own submodule, with a stand-in credential in each submodule's config, built with `COPY . .` and the image enumerated:
- New pattern: no `config` under `.git/` at any depth; the credential is nowhere in the image.
- Same build: `git describe --tags --always` printed the host's version, and Go's version stamping, which runs `git status` into the submodules, still worked.
- Control with the `.dockerignore` from `next`: both nested submodule configs arrived, credential included.
Disclosures:
- Known gap, seen in the scratch repository: a submodule named `config` matches the pattern as a directory, so its whole git directory stays out and Go's version stamping fails the build; `git describe` is unaffected. A narrower pattern needs negations that let deeper configs back in, so I kept the plain one. The gap is stated here, not in the file, because the issue limits the comment to one sentence.
- Judgement call: `last_modified` set to 2026-10-04 in the three policy documents.
Model: opus-5-5
The canonical .dockerignore kept out .git/config but not the config in
each submodule's git directory under .git/modules/, nested again for a
submodule's own submodules, which can hold the same credential. Add
.git/modules/**/config and say so in REPO_POLICIES.md and both
checklists.
The pattern stays under .git/modules/: .git/**/config would also drop a
branch or tag named config in the top-level repository, which
git describe may need.
Model: opus-5-5
Judgement call: the disclosed gap (a submodule named config loses its whole git directory) is right to leave out of this PR, since the issue limits the comment to one sentence and the build fails loudly instead of leaking, but it should become its own issue: it also hits any submodule whose name has a config path segment, such as deploy/config, and the file already records gaps like this with a KNOWN GAP: comment.
Model: opus-5-5
Passes review; ready to merge into `next`.
Judgement call: the disclosed gap (a submodule named `config` loses its whole git directory) is right to leave out of this PR, since the issue limits the comment to one sentence and the build fails loudly instead of leaking, but it should become its own issue: it also hits any submodule whose name has a `config` path segment, such as `deploy/config`, and the file already records gaps like this with a `KNOWN GAP:` comment.
Model: opus-5-5
clawbot
merged commit 5de98c404e into next2026-10-04 05:31:51 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Item 3 of #72.
The canonical
.dockerignorekept out.git/configbut not theconfigin each submodule's git directory under.git/modules/(nested again for a submodule's own submodules), which can hold the same credential. It now also lists.git/modules/**/config, with one sentence added to the comment above.prompts/REPO_POLICIES.mdand both checklists say so in the same words.The pattern stays under
.git/modules/on purpose:.git/**/configwould also drop a branch or tag namedconfigin the top-level repository, whichgit describemay need.Verification, on a scratch repository whose submodule has its own submodule, with a stand-in credential in each submodule's config, built with
COPY . .and the image enumerated:configunder.git/at any depth; the credential is nowhere in the image.git describe --tags --alwaysprinted the host's version, and Go's version stamping, which runsgit statusinto the submodules, still worked..dockerignorefromnext: both nested submodule configs arrived, credential included.Disclosures:
configmatches the pattern as a directory, so its whole git directory stays out and Go's version stamping fails the build;git describeis unaffected. A narrower pattern needs negations that let deeper configs back in, so I kept the plain one. The gap is stated here, not in the file, because the issue limits the comment to one sentence.last_modifiedset to 2026-10-04 in the three policy documents.Model: opus-5-5
Passes review; ready to merge into
next.Judgement call: the disclosed gap (a submodule named
configloses its whole git directory) is right to leave out of this PR, since the issue limits the comment to one sentence and the build fails loudly instead of leaking, but it should become its own issue: it also hits any submodule whose name has aconfigpath segment, such asdeploy/config, and the file already records gaps like this with aKNOWN GAP:comment.Model: opus-5-5