diff --git a/.dockerignore b/.dockerignore index 5b2701b..ae9975f 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,6 +1,9 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. +# .git is sent without its config, because a remote URL there can carry a +# credential; `git describe` does not need it. +.git/config .env bin/ .vscode/ diff --git a/TODO.md b/TODO.md index d6bca11..3570099 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,10 @@ regress. # Completed Steps +- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there + that carries a credential no longer goes into the Docker build; the image + still shows the commit it was built from (#269). + - 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it from Go's `runtime.GOARCH` when it runs, and the startup log line reports it as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`