Note that stage C's snapshot makes the parityOverlay gitignore rule load-bearing
CB-578 stage C commits a preserved dirty worktree to refs/wip/<branch> with git add -A. The parity overlay copies the primary's environment files into every worktree, so a non-gitignored overlay path now reaches a durable git object instead of only sitting on disk. add -A respects .gitignore, which is what stops it — so the rule documented for CB-581 is now what keeps a secret out of a commit, not just out of a directory.
This commit is contained in:
@@ -187,6 +187,14 @@ public record BridgedConfig(
|
||||
* <em>every</em> profile, so creating either file at the repo root is enough
|
||||
* to make it live. Add a new overlay path to {@code .gitignore} in the same
|
||||
* change that adds it here.
|
||||
* <p>CB-578 stage C raised the stakes: a preserved dirty worktree is now also
|
||||
* committed to {@code refs/wip/<branch>} via {@code git add -A}. The overlay
|
||||
* carries the primary's own environment files into the worktree, so a
|
||||
* non-gitignored overlay path no longer merely sits there as an untracked
|
||||
* file — it gets committed into a git object that survives the worktree's
|
||||
* removal. {@code add -A} respects {@code .gitignore}, which is exactly what
|
||||
* keeps that from happening, so the gitignore rule above is now what stops a
|
||||
* secret from reaching a durable commit.
|
||||
* @param gitTokenEnv name of the host env var holding the git-forge API token; when set, its
|
||||
* value is injected as {@code GITEA_TOKEN} so the worker can open its own PR
|
||||
* at checkpoint (CB-302). {@code null}/blank ⇒ no token is injected
|
||||
|
||||
Reference in New Issue
Block a user