Keep .git/config out of the Docker build context (closes #269)
Check / check (pull_request) Successful in 5m3s
Check / check (pull_request) Successful in 5m3s
.git goes into the build so `make build` can stamp the version, and with it went .git/config, where a remote URL can carry a credential that then stays in the builder stage's layers on the build host. `git describe` does not need it, so .dockerignore now leaves it out. Model: opus-5-5
This commit was merged in pull request #271.
This commit is contained in:
@@ -1,6 +1,9 @@
|
||||
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
||||
# upaas. List no tracked file here: git would see it as deleted in the build and
|
||||
# the version would end in -dirty.
|
||||
# .git is sent without its config, because a remote URL there can carry a
|
||||
# credential; `git describe` does not need it.
|
||||
.git/config
|
||||
.env
|
||||
bin/
|
||||
.vscode/
|
||||
|
||||
Reference in New Issue
Block a user