From db7dda468f26a111b497511896af7a5d9c625fe9 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Sat, 22 Aug 2026 10:23:54 -0700 Subject: [PATCH] chore: anchor artifact ignore rules to repo root; block them from Docker image layers Follow-up to the cherry-picked cleanup: the default.tar.gz profile export was also carried into published container images by the Dockerfile's 'COPY . .' layer because .dockerignore had no matching pattern. Anchor the .gitignore rules to repo root (per review feedback on #91712) and add the same set + /*.tar.gz to .dockerignore so root archives can never reach an image layer again. --- .dockerignore | 7 +++++++ .gitignore | 8 ++++---- 2 files changed, 11 insertions(+), 4 deletions(-) diff --git a/.dockerignore b/.dockerignore index 6425e70abf..8b4cb63c32 100644 --- a/.dockerignore +++ b/.dockerignore @@ -106,3 +106,10 @@ plans/ .gitattributes .hadolint.yaml .mailmap + +# Repo-root debug/export artifacts — must never reach image layers (COPY . .) +/log.txt +/sqlite_leak_fix.png +/*.png.bak +/default.tar.gz +/*.tar.gz diff --git a/.gitignore b/.gitignore index a2d9f96a24..0d26c24a21 100644 --- a/.gitignore +++ b/.gitignore @@ -99,10 +99,10 @@ apps/desktop/src/**/*.d.ts !apps/desktop/src/vite-env.d.ts # Repo-root build/debug artifacts that must never be committed -log.txt -sqlite_leak_fix.png -*.png.bak -default.tar.gz +/log.txt +/sqlite_leak_fix.png +/*.png.bak +/default.tar.gz apps/shared/src/**/*.js apps/shared/src/**/*.js.map apps/shared/src/**/*.d.ts