test-go / test (push) Successful in 1m5s
test-go / integration (push) Successful in 3m30s
release / Build signed APK (releases and dev) (push) Successful in 5m10s
release / Build + push container image (push) Successful in 1m31s
release / Verify release artifacts (tag releases only) (push) Skipped
Three build-hygiene fixes that turned up while explaining the pathspec.
**version.sh derives from what SHIPPED.** It read bare HEAD, so any commit
moved the version — including one touching only CI or a README. Rules 148
and 149 both specify the pathspec form. Now a denylist, and the direction
is the point: as an allowlist the list must be updated by whoever adds a
directory and nothing fails if they don't, so the failure mode is a changed
artifact keeping its old version silently on a green run. Inverted, new
content counts by default.
android/ is deliberately NOT excluded, and that is the subtle part. This
repo ships TWO artifacts from ONE derivation: android/ is in no server
image, but it is the APK's entire source, and excluding it would stop an
Android-only commit from moving the APK's own version — the silent
downgrade the versioning rework exists to prevent. So the list is the
union: exclude only what ships in neither, and accept that an Android
commit also nudges the server's reported version. Over-inclusion across the
two, which is the harmless direction. roundtable/roundtable-android each
keep tighter lists because they are one-artifact repos; don't copy theirs.
**.dockerignore excluded the wrong CI directory.** It named .forgejo/ and
.github/, neither of which this repo has. Gitea Actions reads .gitea/, so
the one directory that exists was the one not excluded. The "Flutter mobile
client" block had also lost its PATTERN when flutter_client/ was deleted,
leaving a comment describing an exclusion that was not happening — android/
never took its place, so 4.1MB of Gradle project entered the context and
busted the `COPY . .` layer on every Android-only change. bin/ excluded too.
**bin/minstrel was tracked** — an 18MB binary last refreshed by a commit
about web test mocks, and re-dirtied by every `make build` since. Untracked
and ignored; the file stays on disk.
Guards are behavioural rather than textual: they build throwaway repos with
pinned commit timestamps and run version.sh against them, so they break when
the derivation changes rather than when the wording does. Falsified — drop
the .gitea exclusion and the CI-only commit moves the version; add an
android exclusion and an Android commit stops moving it; exclude everything
and a source commit refuses.
One honest note on the refusal test: the script already refused an empty
result via the downstream date check, so the new explicit check improves the
diagnostic ("no commit touches the shipped file set — shallow clone?") and
not the safety. The test pins the property, which is defended in depth.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SQ31KQpYbStyK5y58UmPLH
77 lines
2.1 KiB
Plaintext
77 lines
2.1 KiB
Plaintext
# ---> Go
|
|
# If you prefer the allow list template instead of the deny list, see community template:
|
|
# https://github.com/github/gitignore/blob/main/community/Golang/Go.AllowList.gitignore
|
|
#
|
|
# Binaries for programs and plugins
|
|
*.exe
|
|
*.exe~
|
|
*.dll
|
|
*.so
|
|
*.dylib
|
|
|
|
# Test binary, built with `go test -c`
|
|
*.test
|
|
|
|
# `make build` output. bin/minstrel was tracked until 2026-09-10 — an 18 MB
|
|
# binary committed by accident, last refreshed by a commit about web test
|
|
# mocks, and re-dirtied by every local build since.
|
|
bin/
|
|
|
|
# Bundled Android APK + version sidecar (#397). Populated by CI for
|
|
# tag releases; never committed. README in client/ explains the flow.
|
|
client/minstrel.apk
|
|
client/minstrel.apk.version
|
|
|
|
# Output of the go coverage tool, specifically when used with LiteIDE
|
|
*.out
|
|
|
|
# Dependency directories (remove the comment below to include it)
|
|
# vendor/
|
|
|
|
# Go workspace file
|
|
go.work
|
|
go.work.sum
|
|
|
|
# env file
|
|
.env
|
|
|
|
|
|
# Superpowers brainstorming companion sessions
|
|
.superpowers/
|
|
|
|
# Agent-authored design specs and implementation plans (kept local; the
|
|
# canonical record lives in commit messages and the running code).
|
|
docs/superpowers/
|
|
|
|
# Per-machine Claude Code settings + remember-skill memory artifacts +
|
|
# project-level Claude/AI instruction files. All operator-scoped; the
|
|
# canonical project memory lives under ~/.claude/projects/ outside the
|
|
# repo. CLAUDE.md/AGENTS.md/GEMINI.md stay on the operator's machine
|
|
# only — they're tool-specific working notes, not project artifacts.
|
|
.claude/
|
|
.remember/
|
|
CLAUDE.md
|
|
AGENTS.md
|
|
GEMINI.md
|
|
.cursorrules
|
|
.windsurfrules
|
|
.aider.conf.yml
|
|
|
|
# Native Android (Kotlin/Compose) — M8 rewrite
|
|
android/.gradle/
|
|
android/.kotlin/
|
|
android/.idea/
|
|
android/build/
|
|
android/app/build/
|
|
android/local.properties
|
|
android/*.iml
|
|
android/app/*.iml
|
|
# Release signing material — keystore + extracted credentials live local
|
|
# only; the canonical copy is the Gitea repo secret (ANDROID_KEYSTORE_B64
|
|
# + the alias/password secrets). Losing the local file is fine; losing
|
|
# the secret means rebuilding the keystore + reinstalling all clients.
|
|
android/*.keystore
|
|
android/*.keystore.*
|
|
android/*.jks
|
|
android/keystore.properties
|