Phase 16: CI dependency audit & security checks #15

Merged
luckberg merged 40 commits from gsd/phase-16-ci-dependency-audit-and-security-checks into main 2026-06-13 10:01:01 -04:00
Showing only changes of commit 5819247a01 - Show all commits
+58
View File
@@ -0,0 +1,58 @@
# === Secrets and credentials (NEVER in build context) ===
.env
.env.*
!.env.example
apps/api/scripts/seed-credential.mjs
# === VCS (large and unnecessary) ===
.git
.gitignore
# === Build artifacts (regenerated in-build) ===
**/dist/
**/.dist/
# === Dependencies (reinstalled in-build) ===
**/node_modules/
# === Tests (not needed in build; keep out of prod) ===
apps/api/tests/
apps/api/test/
apps/pwa/e2e/
# === Playwright artifacts ===
apps/pwa/test-results/
apps/pwa/playwright-report/
apps/pwa/blob-report/
.playwright/
.playwright-cli/
# === Planning / docs / dev tooling ===
.planning/
docs/
graphify-out/
.venv/
# === Editor / OS ===
.vscode/
.idea/
.DS_Store
# === CI / dev config files (not needed in image) ===
.gitea/
.markdownlint-cli2.jsonc
.prettierignore
.prettierrc
eslint.config.js
# === SQL dumps (if any) ===
*.sql.dump
*.sql.gz
# NOTE: apps/api/src/db/migrations/*.sql are included in the build context
# because the builder stage's `COPY apps/api ./apps/api` needs them.
# However, migrations are applied at runtime (drizzle-kit migrate), not
# baked into the image — they travel with the app source in builder stage only.
# The production stage does NOT copy apps/api/src directly; it only copies
# apps/api/dist (via --from=builder) and apps/api/package.json.
# So migration .sql files in src/db/migrations/ never reach the production image.