diff --git a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java index b142b62..4c88a05 100644 --- a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java +++ b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java @@ -187,6 +187,14 @@ public record BridgedConfig( * every profile, so creating either file at the repo root is enough * to make it live. Add a new overlay path to {@code .gitignore} in the same * change that adds it here. + *

CB-578 stage C raised the stakes: a preserved dirty worktree is now also + * committed to {@code refs/wip/} via {@code git add -A}. The overlay + * carries the primary's own environment files into the worktree, so a + * non-gitignored overlay path no longer merely sits there as an untracked + * file — it gets committed into a git object that survives the worktree's + * removal. {@code add -A} respects {@code .gitignore}, which is exactly what + * keeps that from happening, so the gitignore rule above is now what stops a + * secret from reaching a durable commit. * @param gitTokenEnv name of the host env var holding the git-forge API token; when set, its * value is injected as {@code GITEA_TOKEN} so the worker can open its own PR * at checkpoint (CB-302). {@code null}/blank ⇒ no token is injected