Skip to content

fix: keep secrets gitignored when adding local plugins - #4

Merged
oantoshchenko merged 2 commits into
mainfrom
fix/gitignore-secrets-last
Jun 14, 2026
Merged

oantoshchenko merged 2 commits into
mainfrom
fix/gitignore-secrets-last

Conversation

@oantoshchenko

Copy link
Copy Markdown
Contributor

Problem

add_gitignore_exemption appended !plugins/<name>/** to the end of .gitignore, after the *.env rule. Because .gitignore is last-match-wins, that exemption re-included the plugin's .env, which atk add's auto-commit then committed. Any local plugin with a root *.env had its secrets tracked (this is how a real plugins/<name>/.env got committed).

Fix

  • init.py — GITIGNORE_CONTENT keeps the secret rules last, behind a shared header constant.
  • git.py — new normalize_gitignore() moves the secret block to the end (idempotent); add_gitignore_exemption and remove_gitignore_exemption now normalize so secrets always win. Adds list_tracked_secrets() + git_rm_cached().
  • atk doctor (new, commands/doctor.py) — repairs an existing ATK Home: re-orders .gitignore and untracks any already-committed secret files (kept on disk), warning to rotate the exposed keys.

Tests

  • Real git check-ignore regression reproducing the bug (plugin .env stays ignored; plugin source stays tracked).
  • normalize_gitignore + atk doctor coverage.
  • Updated the tests that encoded the old append-at-EOF layout.

make check (ruff + mypy + 685 pytest) passes.

🤖 Generated with Claude Code

oantoshchenko and others added 2 commits May 11, 2026 19:51
add_gitignore_exemption appended `!plugins/<name>/**` at the END of
.gitignore — after the `*.env` rule. Since .gitignore is last-match-wins,
that exemption re-included the plugin's .env, which `atk add`'s auto-commit
then committed (this is how a real plugins/<name>/.env got tracked).

- init.py: GITIGNORE_CONTENT keeps the secret rules LAST, behind a shared
  header constant.
- git.py: add normalize_gitignore() (moves the secret block to the end,
  idempotent); add_gitignore_exemption and remove_gitignore_exemption now
  normalize so secrets always win. Add list_tracked_secrets + git_rm_cached.
- new `atk doctor` command (commands/doctor.py): repairs an existing home —
  re-orders .gitignore and untracks any already-committed secret files
  (kept on disk), warns to rotate keys.
- tests: real `git check-ignore` regression for the exemption, plus
  normalize/doctor coverage; updated the tests that encoded the old layout.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Jun 14, 2026

Copy link
Copy Markdown

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment

Thanks for integrating Codecov - We've got you covered ☂️

@oantoshchenko
oantoshchenko merged commit 11b72a9 into main Jun 14, 2026
3 of 4 checks passed
@oantoshchenko
oantoshchenko deleted the fix/gitignore-secrets-last branch June 14, 2026 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant