.gitignore had no secret patterns at all, in a secret manager's repo. It is now the org's standard file from sneak/prompts (.env, .env.*, *.pem, *.key, editor and OS files, node_modules/, .claude/), followed by this repo's own entries: /secret, *.log, *.test, settings.local.json. /secret stays anchored so it cannot match the internal/secret/ package directory. Dropped: **/.DS_Store, cli.test and vault.test (other entries already cover them) and the stale .cursorrules and coverage.out.
.dockerignore gains node_modules and a final newline. .git stays in the build context, per the plan amendment on the issue: since #58 the build stamps the version with git describe. Only .git/config stays excluded, so the build context is the same size as before.
The set of tracked files is unchanged, and no tracked file matches the new patterns. No key material (*.key, *.pem, *.age, .env files) is tracked now or anywhere in the history.
Judgement call: node_modules in .dockerignore is written like the file's other entries, so it matches only at the top of the build context, as the issue asks. The org's current .dockerignore writes **/node_modules. This repo has no JavaScript.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/secret/issues/40.
`.gitignore` had no secret patterns at all, in a secret manager's repo. It is now the org's standard file from `sneak/prompts` (`.env`, `.env.*`, `*.pem`, `*.key`, editor and OS files, `node_modules/`, `.claude/`), followed by this repo's own entries: `/secret`, `*.log`, `*.test`, `settings.local.json`. `/secret` stays anchored so it cannot match the `internal/secret/` package directory. Dropped: `**/.DS_Store`, `cli.test` and `vault.test` (other entries already cover them) and the stale `.cursorrules` and `coverage.out`.
`.dockerignore` gains `node_modules` and a final newline. `.git` stays in the build context, per the plan amendment on the issue: since https://git.eeqj.de/sneak/secret/pulls/58 the build stamps the version with `git describe`. Only `.git/config` stays excluded, so the build context is the same size as before.
The set of tracked files is unchanged, and no tracked file matches the new patterns. No key material (`*.key`, `*.pem`, `*.age`, `.env` files) is tracked now or anywhere in the history.
Judgement call: `node_modules` in `.dockerignore` is written like the file's other entries, so it matches only at the top of the build context, as the issue asks. The org's current `.dockerignore` writes `**/node_modules`. This repo has no JavaScript.
Model: opus-5-5
PASS: the change meets #40 as amended; the branch conflicts with next only in TODO.md (keep both entries) and needs that rebase before merging.
Model: opus-5-5
PASS: the change meets https://git.eeqj.de/sneak/secret/issues/40 as amended; the branch conflicts with `next` only in `TODO.md` (keep both entries) and needs that rebase before merging.
Model: opus-5-5
.gitignore had no secret patterns at all. It is now the org's standard
file, which ignores .env, .env.*, *.pem and *.key and editor and OS
files, plus this repo's /secret (anchored, so internal/secret/ is not
matched), *.log, *.test and settings.local.json. The stale
.cursorrules and coverage.out entries are gone. No tracked file
matches the new patterns.
.dockerignore also leaves out node_modules and ends with a newline.
.git stays in the build context because the build stamps the version
with git describe; .git/config stays excluded.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #40.
.gitignorehad no secret patterns at all, in a secret manager's repo. It is now the org's standard file fromsneak/prompts(.env,.env.*,*.pem,*.key, editor and OS files,node_modules/,.claude/), followed by this repo's own entries:/secret,*.log,*.test,settings.local.json./secretstays anchored so it cannot match theinternal/secret/package directory. Dropped:**/.DS_Store,cli.testandvault.test(other entries already cover them) and the stale.cursorrulesandcoverage.out..dockerignoregainsnode_modulesand a final newline..gitstays in the build context, per the plan amendment on the issue: since #58 the build stamps the version withgit describe. Only.git/configstays excluded, so the build context is the same size as before.The set of tracked files is unchanged, and no tracked file matches the new patterns. No key material (
*.key,*.pem,*.age,.envfiles) is tracked now or anywhere in the history.Judgement call:
node_modulesin.dockerignoreis written like the file's other entries, so it matches only at the top of the build context, as the issue asks. The org's current.dockerignorewrites**/node_modules. This repo has no JavaScript.Model: opus-5-5
PASS: the change meets #40 as amended; the branch conflicts with
nextonly inTODO.md(keep both entries) and needs that rebase before merging.Model: opus-5-5
6cad9daabdto7a8ed5296d