Skip to content

feat: implement issue #146 — Compliance: gitignore_baseline - #148

Merged
don-petry merged 15 commits into
mainfrom
dev-lead/issue-146-20260807-1325
Aug 21, 2026
Merged

don-petry merged 15 commits into
mainfrom
dev-lead/issue-146-20260807-1325

Conversation

@don-petry

@don-petry don-petry commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #146

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • Chores
    • Updated repository configuration and continuous integration workflow formatting.
    • Refined ignore rules to allow encrypted .env.vault files and simplify guidance for repository-specific files.
    • Updated canonical ignore-file verification and added a check ensuring .env.vault files remain trackable.
  • Tests
    • Added regression coverage for .env.vault ignore behavior.

CodeAnt-AI Description

Allow encrypted environment vault files to be committed

What Changed

  • .env.vault files are explicitly allowed in the repository for CI and production decryption
  • Added a regression check that distinguishes an allowed file from a git error
  • Private key files and compressed database dumps remain excluded

Impact

✅ Encrypted environment configuration can be committed
✅ Private keys remain excluded
✅ Git-ignore compliance errors are detected reliably

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@don-petry
don-petry requested a review from a team as a code owner August 7, 2026 13:28
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@codeant-ai

codeant-ai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 725f794 Aug 20, 2026 · 03:36 03:37
✅ Incremental review completed b77d356 Aug 19, 2026 · 07:41 07:42
✅ Incremental review completed 82db49c Aug 18, 2026 · 15:19 15:19
✅ Incremental review completed dbe75a4 Aug 16, 2026 · 04:26 04:27
✅ Incremental review completed a755e38 Aug 15, 2026 · 07:44 07:44

@codeant-ai

codeant-ai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 34 minutes

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1b1cbc8a-0b5e-4eea-9c81-dca8de00ab04

📥 Commits

Reviewing files that changed from the base of the PR and between 82db49c and 3654d04.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 304bd756-cf13-4d16-8534-99f922332e8f

📥 Commits

Reviewing files that changed from the base of the PR and between dbe75a4 and 82db49c.

📒 Files selected for processing (1)
  • tests/gitignore-baseline.bats

Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request permits committed encrypted .env.vault files, updates gitignore guidance, refreshes baseline validation, and adds regression coverage. It also applies formatting-only edits to Dependabot and GitHub Actions configuration.

Changes

Repository maintenance

Layer / File(s) Summary
Gitignore baseline and regression coverage
.gitignore, tests/gitignore-baseline.bats
.gitignore allows .env.vault, updates extension guidance and the logs heading, and the baseline test validates the new digest and rule.
Repository configuration formatting
.github/dependabot.yml, .github/workflows/ci.yml, .github/workflows/dev-lead.yml
Formatting changes preserve the existing Dependabot label, coverage commands, and workflow permission.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 82db4

The change allows encrypted environment vault files while retaining protections for private keys and database dumps; no actionable merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The Dependabot and workflow changes are unrelated to the gitignore compliance objective. Remove unrelated Dependabot and workflow changes from this pull request.
Linked Issues check ❓ Inconclusive The context does not confirm that the required managed block matches the canonical organization block verbatim. Verify the managed block against the canonical organization block and pin the canonical baseline hash.
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: implementing the gitignore compliance update for issue #146.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-146-20260807-1325

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the .gitignore file to adopt a comprehensive, managed secrets baseline for petry-projects, covering various sensitive credentials, cloud configs, database dumps, and IDE files. Feedback on the changes highlights that the broad .env.* wildcard will accidentally ignore .env.vault, which is meant to be committed to source control for dotenv-vault to function properly, and suggests adding a negation rule for it.

Comment thread .gitignore
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 7, 2026 13:35
@don-petry
don-petry disabled auto-merge August 7, 2026 13:42
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 7, 2026 13:44
@don-petry
don-petry disabled auto-merge August 7, 2026 13:52
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 7, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
## Summary
**Bot: SonarCloud** (no actionable issues)  
The SonarCloud Quality Gate report shows a passing result with 0 new issues, 0 accepted issues, and 0 security hotspots. No code changes needed based on this report.
**Issues addressed: 1**
- **gemini-code-assist review thread (`.env.vault` negation)**: Already fixed in `.gitignore` at line 37 with `!.env.vault`, ensuring dotenv-vault encrypted file is committed while `.env.vault.keys` remains ignored. [replied + thread resolved]
**Files changed:** 
- `.gitignore` (already has correct negations for `.env.vault` and templates)
- `tests/gitignore-baseline.bats` (new compliance test file)
**Tier 1 Blocker - Coverage Check (FAILURE)**  
The coverage CI check is failing with `E: Unable to locate package kcov` in the ubuntu-latest (24.04) environment. This is an environmental issue: the `kcov` package is not available in Ubuntu 24.04 standard repositories. The PR's test file and gitignore baseline are valid; the failure is due to missing system dependency in the CI runner, not a code issue. This would require updating the CI workflow to install kcov from an alternative source (building from source or using a third-party PPA), which is outside the scope of this PR's changed files.

@don-petry
don-petry enabled auto-merge (squash) August 7, 2026 13:55
@don-petry
don-petry disabled auto-merge August 7, 2026 13:56
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 7, 2026 14:06
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/ci.yml Fixed
@don-petry
don-petry disabled auto-merge August 7, 2026 14:08
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead Fix CI — applied

PR: #148 | SHA: c4a6e5050f2126e9d6a07f16a158be9a8eaa1a1d
Fix committed and pushed. Waiting for CI.

@don-petry
don-petry enabled auto-merge (squash) August 7, 2026 14:09
@don-petry
don-petry disabled auto-merge August 7, 2026 14:10
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 7, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

donpetry-bot and others added 11 commits August 18, 2026 10:18
…ebase

.gitignore was truncated to 15 lines (losing the full secrets baseline)
and dependabot.yml had a leftover conflict marker, both introduced by
automated conflict resolution across 118 scaffold/re-seed commits.

Restored both files to their correct post-rebase state matching the
original PR tip's intent: full 420-line secrets baseline in .gitignore
and the standard npm-only dependabot.yml.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
git check-ignore exits 1 for a non-ignored path but 128 on error; the
nonzero assertion would mask errors as passes (CodeRabbit review).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@codeant-ai

codeant-ai Bot commented Aug 18, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@codeant-ai

codeant-ai Bot commented Aug 19, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
- **All CI checks**: Passing (no failures, timeouts, or action required)
- **No blockers**: Zero Tier 1 issues remain
---
## Summary
**Bot:** CodeRabbit (primary) + CodeAnt (informational)
**Issues addressed:** 1
- `.env.vault test requires exact status 1 from git check-ignore`: Fixed in commit 82db49c [replied + thread already resolved]
**Files changed:** `tests/gitignore-baseline.bats`
**Skipped (informational):** 1 (CodeAnt promotional message)
**Conclusion:** No further action needed. The actionable issue identified by CodeRabbit has been fixed and the review thread properly resolved. All CI checks pass.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0 (already fixed in prior commit 82db49c)
Files changed: none
Skipped (informational): 1 – SonarCloud quality gate passed (neutral overview, not actionable)
```

@codeant-ai

codeant-ai Bot commented Aug 20, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
## Summary
**Bot:** (No specific bot name provided — analyzing CodeAnt comment + all review threads)
**Issues addressed:** 0 (no new changes needed)
**Status:** All actionable issues from reviewers have already been fixed in this PR:
1. **CodeRabbit finding (RESOLVED)**: The test in `tests/gitignore-baseline.bats` line 127 already correctly checks for exactly `status -eq 1` instead of any nonzero status. Marked as "✅ Addressed in commits bf5a2b8 to 82db49c."
2. **Gemini-code-assist concern (ADDRESSED)**: The `.env.vault` negation rule already exists in `.gitignore` line 37 (`!.env.vault`), ensuring the encrypted dotenv-vault ciphertext is committed despite the broad `.env.*` ignore pattern.
3. **CodeAnt bot comment**: Purely informational/marketing content with no specific, actionable defects tied to files/lines — nothing to fix per task constraints.
**CI status:** All required checks passing (success/skipped), no blockers.
**Files changed:** None — the working tree is clean.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
- Quality Gate report: Neutral overview with no actionable defects (0 new issues found)
Files changed: None
Skipped (informational): 1
```
**No changes required.** The PR passes all automated checks and has no Tier 1 blockers. The SonarCloud comment is a passing quality gate report with no specific issues to address.

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: 3654d0495ec612bc8426d7e424d23d138fbe5303
Review mode: triage-approved (single reviewer)

Summary

Evolves the canonical L1 secrets-baseline .gitignore in the template repo to permit committing encrypted dotenv-vault ciphertext (!.env.vault), plus trivial whitespace/newline formatting in three workflow/config files. Change is narrow, tested, and CI-green.

Linked issue analysis

Closes #146 (Compliance: gitignore_baseline). The PR adds a scoped negation !.env.vault to the managed baseline and a regression test asserting the file is not ignored. This substantively addresses the compliance goal of allowing encrypted vault files while keeping plaintext secrets excluded.

Findings

  • [safe] Negation is correctly scoped. !.env.vault un-ignores only the encrypted-by-design vault file. The sibling .env.vault.keys (plaintext decryption keys) remains git-ignored via both .env.* and an explicit entry — the key security property for dotenv-vault is preserved.
  • [safe] Baseline checksum updated in lockstep. GITIGNORE_L1_SHA256 in tests/gitignore-baseline.bats was regenerated to match the edited block; the baseline bats suite passes in CI. Editing the L1 block + bumping the checksum is the legitimate workflow in this canonical template repo (not a downstream consumer).
  • [cleanup] Removed a dangling doc reference. The old L2 comment pointed to standards/gitignore-standard.md, which does not exist in the repo tree; the PR replaces it with an accurate in-repo note.
  • [trivial] Workflow/config edits to ci.yml, dev-lead.yml, and dependabot.yml are comment-alignment and trailing-newline only — no permission, trigger, or logic changes; no Actions security smells.
  • Note: the run_secret_scanning MCP tool is not exposed in this environment; relied on the passing gitleaks and CodeQL checks instead.

CI status

All required checks green: build-and-test, coverage, CodeQL, Analyze (actions), SonarCloud, gitleaks secret scan, agent-shield/AgentShield. Ecosystem-specific audit jobs skipped as expected. mergeStateStatus is BLOCKED only pending required review. CodeRabbit's latest state is APPROVED; no unresolved, non-outdated review threads.


Reviewed automatically by the PR-review agent (single-reviewer). Reply if you need a human review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compliance: gitignore_baseline

3 participants