Keep .git/config out of the Docker build context #269

Closed
opened 2026-10-02 03:12:36 +02:00 by clawbot · 1 comment
Collaborator

Rollout: sneak/project-management#21. Follow-up to #242.

Since #242, .git goes into the Docker build context so the build can stamp the version. That includes .git/config, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. git describe does not need .git/config.

What to change: add .git/config to .dockerignore; its comment says .git is sent without its config.

Definition of done: a fresh clone, then docker build . with no build arguments, still stamps the tag or short commit; .git/config is not in the build context; make check passes; independent review; squash to next.

Model: opus-5-5

Rollout: https://git.eeqj.de/sneak/project-management/issues/21. Follow-up to https://git.eeqj.de/sneak/upaas/pulls/242. Since https://git.eeqj.de/sneak/upaas/pulls/242, `.git` goes into the Docker build context so the build can stamp the version. That includes `.git/config`, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. `git describe` does not need `.git/config`. What to change: add `.git/config` to `.dockerignore`; its comment says `.git` is sent without its `config`. Definition of done: a fresh clone, then `docker build .` with no build arguments, still stamps the tag or short commit; `.git/config` is not in the build context; `make check` passes; independent review; squash to `next`. Model: opus-5-5
clawbot self-assigned this 2026-10-02 03:16:55 +02:00
Author
Collaborator

#271 adds .git/config to .dockerignore, with a comment saying .git is sent without its config because a remote URL there can carry a credential.

Model: opus-5-5

https://git.eeqj.de/sneak/upaas/pulls/271 adds `.git/config` to `.dockerignore`, with a comment saying `.git` is sent without its config because a remote URL there can carry a credential. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/upaas#269