Skip to content

Epic: Formalize + enforce the org .gitignore minimum baseline (secrets L1) with per-repo extension (L2) #801

Description

@don-petry

Tracked stories (DAG)


Formalize, distribute, and blockingly enforce an org-wide .gitignore minimum baseline — a language-agnostic secrets-only layer that every repo carries verbatim (L1), while each repo freely extends it with its own ecosystem/OS entries (L2).

Current state (verified, not greenfield)

A strong secrets-only baseline already exists at /.gitignore (396 lines) and is referenced by standards/push-protection.md. But it is under-formalized, under-adopted, and weakly enforced:

  1. Template gap — repo-template/.gitignore is 15 ad-hoc lines missing *.pem/*.key; new repos start non-compliant even against today's 3-substring check.
  2. Adoption gap — only 4 of 10 repos carry the real baseline (bmad-bgreat-suite, TalkTerm, ContentTwin, .github-private); the other 6 have hand-rolled gitignores with no cloud/SSH/tfvars coverage.
  3. Enforcement gap — pp_check_gitignore_secrets_block() checks only 3 substrings at warning severity; the documented rule ("MUST start from the baseline") is not actually enforced.
  4. Distribution gap — detection only; nothing seeds or syncs the baseline (grep gitignore in deploy-standard-workflows.sh and bootstrap-new-repo.sh = 0).

The DAG

#797 STANDARDIZE ── standalone standards/gitignore-standard.md (L1/L2 model) +
     wrap the L1 secrets block in BEGIN/END markers in /.gitignore.   [ROOT]
        │
        ├── #798 SEED + DISTRIBUTE ── marker-wrapped block into repo-template +
        │        bootstrap-new-repo.sh + deploy sync; shared idempotent
        │        upsert_gitignore_baseline() (L2 preserved).
        │
        └── #799 ENFORCE ── check_gitignore_baseline: block present + unmodified
                 (hash match), severity ERROR, via the existing
                 compliance-audit engine. No new workflow. L2 never inspected.
                          │
   #800 BACKFILL + REMEDIATE ── remediation hook + fleet back-fill of the 6
        non-baseline repos so the now-blocking check goes green.  (after #798 & #799)

Design — the minimum baseline

Layer Content Owner Enforced Extendable
L1 secrets baseline the 396-line block, wrapped in BEGIN/END petry-projects secrets baseline markers central (.github) yes — error/blocking, verbatim no (drift = finding)
L2 ecosystem/OS node_modules/, target/, __pycache__/, .DS_Store, … (github/gitignore templates) per-repo, below END marker no yes, freely

Enforcement engine

Wired through the existing compliance-audit-and-improvement.yml (Job 1 → compliance-audit.sh / lib/push-protection.sh → findings → issues). We extend a check function, not add a workflow. Per decision, L1 lands at error severity (blocking tier).

Epic acceptance criteria

Notes / decisions

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions