Repository navigation
fix: keep secrets gitignored when adding local plugins - #4
Merged
Merged
Conversation
add_gitignore_exemption appended `!plugins/<name>/**` at the END of .gitignore — after the `*.env` rule. Since .gitignore is last-match-wins, that exemption re-included the plugin's .env, which `atk add`'s auto-commit then committed (this is how a real plugins/<name>/.env got tracked). - init.py: GITIGNORE_CONTENT keeps the secret rules LAST, behind a shared header constant. - git.py: add normalize_gitignore() (moves the secret block to the end, idempotent); add_gitignore_exemption and remove_gitignore_exemption now normalize so secrets always win. Add list_tracked_secrets + git_rm_cached. - new `atk doctor` command (commands/doctor.py): repairs an existing home — re-orders .gitignore and untracks any already-committed secret files (kept on disk), warns to rotate keys. - tests: real `git check-ignore` regression for the exemption, plus normalize/doctor coverage; updated the tests that encoded the old layout. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Welcome to Codecov 🎉Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests. ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment Thanks for integrating Codecov - We've got you covered ☂️ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
add_gitignore_exemptionappended!plugins/<name>/**to the end of.gitignore, after the*.envrule. Because.gitignoreis last-match-wins, that exemption re-included the plugin's.env, whichatk add's auto-commit then committed. Any local plugin with a root*.envhad its secrets tracked (this is how a realplugins/<name>/.envgot committed).Fix
init.py—GITIGNORE_CONTENTkeeps the secret rules last, behind a shared header constant.git.py— newnormalize_gitignore()moves the secret block to the end (idempotent);add_gitignore_exemptionandremove_gitignore_exemptionnow normalize so secrets always win. Addslist_tracked_secrets()+git_rm_cached().atk doctor(new,commands/doctor.py) — repairs an existing ATK Home: re-orders.gitignoreand untracks any already-committed secret files (kept on disk), warning to rotate the exposed keys.Tests
git check-ignoreregression reproducing the bug (plugin.envstays ignored; plugin source stays tracked).normalize_gitignore+atk doctorcoverage.make check(ruff + mypy + 685 pytest) passes.🤖 Generated with Claude Code