Send .git without its config; correct shallow-clone and version comments
.dockerignore lists .git/config, which holds the clone's remote URL and any credential in it; the build stage is the final image, so it would otherwise ship. git describe does not need it. The build-context test asserts the entry, and the README says the image carries .git without its config. The README now says a shallow clone stamps a tag only when the cloned commit itself carries one, and otherwise the short commit. The comment in src/index.ts says a build reports the version script/build stamps into dist/package.json, and package.json's own version only from source. Model: opus-5-5
This commit is contained in:
@@ -54,6 +54,12 @@ describe(".dockerignore", () => {
|
||||
expect(dockerignore).not.toContain(".git/");
|
||||
});
|
||||
|
||||
// The build stage is the final image, so a .git/config sent in would
|
||||
// ship the clone's remote URL and any credential in it.
|
||||
it("sends .git without its config", () => {
|
||||
expect(dockerignore).toContain(".git/config");
|
||||
});
|
||||
|
||||
// BuildKit lets a `Dockerfile.dockerignore` shadow the root one; such a
|
||||
// file would silently give the build a different, unreviewed context —
|
||||
// and eslint's flat config does not ignore dot-directories, so a stray
|
||||
|
||||
Reference in New Issue
Block a user