package: exclude the .audit run stamp beside /audit - #257
Open
thedavidmeister wants to merge 1 commit into
Open
thedavidmeister wants to merge 1 commit into
thedavidmeister wants to merge 1 commit into
Conversation
Dot-entries ship unless named, so .audit/runs.jsonl and .audit/scope.json reached the package and moved the content hash the publish gate compares. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 37 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #172
.soldeerignoreis a deny list against an include-everything default, and everydot-entry that must not ship has its own line —
.github,.vscode,.gitignore,.pre-commit-config.yaml. Line 11 excludes/audit, which settlesthat audit metadata is not package content. The sibling
.audit/directory thatthe audit convention writes —
.audit/runs.jsonl,.audit/scope.json— had noline, so it shipped.
Reproduced with
forge soldeer push --dry-runin this branch's worktree. Beforethe change the zip's top level is
and after it is
with
audit/protofire/*absent on both sides, which is line 11 working and thedot-sibling slipping past it.
The cost of shipping it is not just the bytes:
test/and.audit/are insidethe content hash the autopublish gate compares, so an audit stamp commit mints a
rain-factoryrevision with no source delta, and every later audit repeats it./auditbeside it is the shape the sibling reposrain.deployandrain.datacontractalready carry..soldeerignoreis also #144's and #171's file, one entry each; all three editsare disjoint lines and each stands alone.
QA
from the forge suite. The before/after dry-run zips above are the
discriminating evidence.
src/ortest/change, so there is no behaviourto mutate.
forge soldeer push --dry-runactually produces, rather thanreading the ignore list and reasoning about what it matches.
.audit/reaching the package; coveredA. The whole list was re-derived from the dry-run zip rather than from the
file, which is how the general form was checked: the only remaining top-level
entries in the package are
src/,test/,README.md,LICENSEandLICENSES/, andtest/is [F40] [LOW] .soldeerignore does not exclude test/, so the published package ships uncompilable test sources and republishes on every test-only merge #144's issue, not a second instance of this one.🤖 Generated with Claude Code