From 5c836c085d486f17db454658cee23c6f4f166b58 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Fri, 2 Oct 2026 04:43:03 +0200 Subject: [PATCH] Keep .git/config out of the Docker build context (closes #269) .git goes into the build so `make build` can stamp the version, and with it went .git/config, where a remote URL can carry a credential that then stays in the builder stage's layers on the build host. `git describe` does not need it, so .dockerignore now leaves it out. Model: opus-5-5 --- .dockerignore | 3 +++ TODO.md | 4 ++++ 2 files changed, 7 insertions(+) diff --git a/.dockerignore b/.dockerignore index 5b2701b..ae9975f 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,6 +1,9 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. +# .git is sent without its config, because a remote URL there can carry a +# credential; `git describe` does not need it. +.git/config .env bin/ .vscode/ diff --git a/TODO.md b/TODO.md index d6bca11..3570099 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,10 @@ regress. # Completed Steps +- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there + that carries a credential no longer goes into the Docker build; the image + still shows the commit it was built from (#269). + - 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it from Go's `runtime.GOARCH` when it runs, and the startup log line reports it as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`