check / check (push) Waiting to run
A submodule that keeps its own `.git` directory, instead of one under `.git/modules/`, still shipped `sub/.git/config` into the build context, credential included. Both git patterns in the canonical `.dockerignore` now start with `**/`: `**/.git/config` and `**/.git/modules/**/config`. A submodule whose name has a `config` segment (`config`, `deploy/config`, `config/lib`) still loses its whole git directory, because the pattern also matches that directory, and Go's version stamping then fails the build loudly. The file records this as a known gap with the way around it, `git submodule add --name`; closing it needs a wildcard re-include that makes every build walk excluded directories. `prompts/REPO_POLICIES.md` and both checklists say the same. Model: opus-5-5
73 lines
2.8 KiB
Plaintext
73 lines
2.8 KiB
Plaintext
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
|
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
|
# `/` and an unprefixed pattern is anchored at the context root. Every
|
|
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
|
# `certs/server.key` still ship while this file reads as solved. Only
|
|
# genuinely root-anchored entries go unprefixed. Never transplant these
|
|
# into .gitignore, where `**/` is wrong.
|
|
#
|
|
# Matching is case-sensitive, so secrets use character ranges rather
|
|
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
|
#
|
|
# Extend with this repo's own host-built artifacts, written anchored:
|
|
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
|
# deletes the package directory from the context.
|
|
|
|
# .git is sent without its config. Without a VERSION build argument the
|
|
# stage that compiles runs `git describe --tags --always` on .git, which
|
|
# does not need .git/config; that file can hold a credential, such as a
|
|
# password in a remote URL or the token the CI checkout step stores there.
|
|
# Each submodule keeps a config with the same exposure in its git directory
|
|
# under .git/modules/, nested again for a submodule's own submodules, or in
|
|
# its own .git directory when it keeps one.
|
|
# KNOWN GAP: a submodule whose name has a `config` segment (`config`,
|
|
# `deploy/config`, `config/lib`) loses its whole git directory, because
|
|
# `**/.git/modules/**/config` also matches that segment's directory
|
|
# under .git/modules/. Go's version stamping then fails the build;
|
|
# nothing leaks. Name such a submodule without that segment:
|
|
# `git submodule add --name`.
|
|
**/.git/config
|
|
**/.git/modules/**/config
|
|
|
|
# Agent scratch: one full checkout of the repo per in-flight agent.
|
|
# Anchored because it occurs once where agents run at the repo root.
|
|
# KNOWN GAP: a repo running agents in subdirectories still ships
|
|
# `services/api/.claude/` and must add its own anchored entry.
|
|
.claude
|
|
|
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
|
# convention. Re-include a committed template with a negation if the
|
|
# build needs one: `!docs/example.env`.
|
|
**/*.[eE][nN][vV]
|
|
**/.[eE][nN][vV].*
|
|
**/.[eE][nN][vV][rR][cC]
|
|
|
|
# Private keys and the bundles carrying them. Public certificates
|
|
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
|
**/*.[pP][eE][mM]
|
|
**/*.[kK][eE][yY]
|
|
**/*.[pP]12
|
|
**/*.[pP][fF][xX]
|
|
**/[iI][dD]_[rR][sS][aA]
|
|
**/[iI][dD]_[dD][sS][aA]
|
|
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
|
**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
|
**/[iI][dD]_[eE][dD]25519
|
|
**/[iI][dD]_[eE][dD]25519_[sS][kK]
|
|
|
|
# Dependencies: restored inside the image, never copied in.
|
|
**/node_modules
|
|
|
|
# OS metadata.
|
|
**/.DS_Store
|
|
**/Thumbs.db
|
|
|
|
# Editor state: never a build input, and it churns COPY.
|
|
**/*.swp
|
|
**/*.swo
|
|
**/*~
|
|
**/*.bak
|
|
**/.idea
|
|
**/.vscode
|
|
**/*.sublime-*
|