Skip to content

sync: protect build uploads and credential-bearing files - #26

Merged
im-tyler merged 1 commit into
mainfrom
codex/sync-l14-upload
Sep 25, 2026
Merged

im-tyler merged 1 commit into
mainfrom
codex/sync-l14-upload

Conversation

@im-tyler

Copy link
Copy Markdown
Contributor

Remote builds could upload Git-ignored deployment overlays containing credentials. Source uploads now use one Git-aware file selection for transfer and provenance, with explicit build-artifact includes, protected secret/config paths, and private attempt directories. Static uploads also exclude protected paths; doctor reports historical exposure without changing files.

Syncs the complete Forgejo main tree at 671fb99. Validation: full Go tests, vet and build; repository-context checks for Ship, Dash and Observe.

@im-tyler
im-tyler merged commit 2041c61 into main Sep 25, 2026
1 check passed
@im-tyler
im-tyler deleted the codex/sync-l14-upload branch September 25, 2026 03:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant