Since #242, .git goes into the Docker build context so the build can stamp the version. That includes .git/config, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. git describe does not need .git/config.
What to change: add .git/config to .dockerignore; its comment says .git is sent without its config.
Definition of done: a fresh clone, then docker build . with no build arguments, still stamps the tag or short commit; .git/config is not in the build context; make check passes; independent review; squash to next.
Model: opus-5-5
Rollout: https://git.eeqj.de/sneak/project-management/issues/21. Follow-up to https://git.eeqj.de/sneak/upaas/pulls/242.
Since https://git.eeqj.de/sneak/upaas/pulls/242, `.git` goes into the Docker build context so the build can stamp the version. That includes `.git/config`, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host. `git describe` does not need `.git/config`.
What to change: add `.git/config` to `.dockerignore`; its comment says `.git` is sent without its `config`.
Definition of done: a fresh clone, then `docker build .` with no build arguments, still stamps the tag or short commit; `.git/config` is not in the build context; `make check` passes; independent review; squash to `next`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-02 03:16:55 +02:00
#271 adds .git/config to .dockerignore, with a comment saying .git is sent without its config because a remote URL there can carry a credential.
Model: opus-5-5
https://git.eeqj.de/sneak/upaas/pulls/271 adds `.git/config` to `.dockerignore`, with a comment saying `.git` is sent without its config because a remote URL there can carry a credential.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Rollout: sneak/project-management#21. Follow-up to #242.
Since #242,
.gitgoes into the Docker build context so the build can stamp the version. That includes.git/config, and a clone whose remote URL carries a credential sends it into the build, where it stays in the builder stage's layers on the build host.git describedoes not need.git/config.What to change: add
.git/configto.dockerignore; its comment says.gitis sent without itsconfig.Definition of done: a fresh clone, then
docker build .with no build arguments, still stamps the tag or short commit;.git/configis not in the build context;make checkpasses; independent review; squash tonext.Model: opus-5-5
#271 adds
.git/configto.dockerignore, with a comment saying.gitis sent without its config because a remote URL there can carry a credential.Model: opus-5-5