[Story] Git-ignore local secrets and environment files #20

Merged
kpcto merged 1 commits from feature/19 into main 2026-08-26 21:37:39 +00:00
Member

What changed

Adds a root .gitignore (new file only — no existing tracked file or content touched):

# Dependencies
node_modules/

# Local environment files and secrets
.env
.env.*

This keeps local environment files and credentials (.env, .env.local, API tokens) and dependency directories from ever being committed by accident.

Criterion → test

Acceptance criterion Verification
A .gitignore at the repo root ignores .env, .env.*, and node_modules git check-ignore -v .env .env.local node_modules matches all three against .gitignore lines 4–6
git check-ignore .env reports the file as ignored after the change git check-ignore .env → prints .env, exit code 0
No currently tracked file is removed by the new ignore rules git ls-files contains no .env*/node_modules paths; after staging, git status shows only A .gitignore (no deletions)
Existing test suite stays green node --test (what pnpm test runs) → 53 passed, 0 failed

Risks

  • Single new file, revertible by reverting one commit; no migration (per rollback note).
  • .env.example would also be ignored by the .env.* rule — accepted, as the story's acceptance criteria require .env.* to be ignored.
  • No secret scanning, credential rotation, or backend changes (out of scope).
## What changed Adds a root `.gitignore` (new file only — no existing tracked file or content touched): ```gitignore # Dependencies node_modules/ # Local environment files and secrets .env .env.* ``` This keeps local environment files and credentials (`.env`, `.env.local`, API tokens) and dependency directories from ever being committed by accident. ## Criterion → test | Acceptance criterion | Verification | | --- | --- | | A `.gitignore` at the repo root ignores `.env`, `.env.*`, and `node_modules` | `git check-ignore -v .env .env.local node_modules` matches all three against `.gitignore` lines 4–6 | | `git check-ignore .env` reports the file as ignored after the change | `git check-ignore .env` → prints `.env`, exit code 0 | | No currently tracked file is removed by the new ignore rules | `git ls-files` contains no `.env*`/`node_modules` paths; after staging, `git status` shows only `A .gitignore` (no deletions) | | Existing test suite stays green | `node --test` (what `pnpm test` runs) → 53 passed, 0 failed | ## Risks - Single new file, revertible by reverting one commit; no migration (per rollback note). - `.env.example` would also be ignored by the `.env.*` rule — accepted, as the story's acceptance criteria require `.env.*` to be ignored. - No secret scanning, credential rotation, or backend changes (out of scope).
bot-implementer added 1 commit 2026-08-26 19:34:47 +00:00
Add root .gitignore for local env files and node_modules
CI / Run tests (pull_request) Successful in 29s
CI / Secret scan (gitleaks) (pull_request) Successful in 57s
e186faeb44
Ignores .env, .env.*, and node_modules/ at any depth so local secrets and dependency directories can never be committed accidentally. Single-file hygiene change; no tracked files affected. Closes #19.
kpcto closed this pull request 2026-08-26 21:13:23 +00:00
kpcto reopened this pull request 2026-08-26 21:18:44 +00:00
kpcto merged commit 2a321ad677 into main 2026-08-26 21:37:39 +00:00
kpcto deleted branch feature/19 2026-08-26 21:37:40 +00:00
Sign in to join this conversation.