feat: add org-default .gitignore baseline#43
Merged
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces an organization-default .gitignore baseline (configs/gitignore) to prevent committing secrets, credentials, and AI-assistant local state, and updates the README.md with instructions on how to append it during repository scaffolding. The review feedback suggests narrowing down the overly broad *credentials* wildcard pattern to avoid ignoring valid source files, and adding an explicit newline before appending to .gitignore in the scaffolding command to prevent formatting issues.
This was referenced Jun 18, 2026
Merged
7b9d52e to
725acd9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
configs/gitignore— an org-default.gitignorebaseline — as a new sharedinheritance surface, consumed the same copy-at-scaffold way as the other
dryvist/.githubconfigs. Consolidates common ignore patterns (environment files,credential/secret material, cloud-provider state, Terraform/OpenTofu state, and
AI-assistant local artifacts) into one canonical source so repos don't each
hand-roll inconsistent coverage.
README updated (inheritance table, API table, usage snippet).
Carve-outs deliberately preserved
.envrcstays committed (direnv convention).*.sops.yaml/.ymlciphertext stays committed..terraform.lock.hclstays committed..claude/settings.json,.claude/rules/,CLAUDE.md,AGENTS.md) is intentionally not ignored.Rollout
Establishes the source of truth; does not retro-apply. Repos adopt by appending
configs/gitignoreand de-duping.🤖 Generated with Claude Code