Explorar o código

code-modernization: assess writes the full quarantine ignore set

assess only added SECRETS.local.md to analysis/.gitignore, leaving
*.local.patch uncovered until harden's own Step 0 ran. Both patterns are
now written by whichever command runs first.
Morgan Lunt hai 3 meses
pai
achega
4f49895abd
Modificáronse 1 ficheiros con 4 adicións e 2 borrados
  1. 4 2
      plugins/code-modernization/commands/modernize-assess.md

+ 4 - 2
plugins/code-modernization/commands/modernize-assess.md

@@ -151,8 +151,10 @@ need explained.
 discovered credential values must never appear in it. If the
 security-auditor found any hardcoded credentials:
 
-1. Ensure `analysis/.gitignore` exists and contains the line
-   `SECRETS.local.md` (create or append as needed). If the project is a
+1. Ensure `analysis/.gitignore` exists and contains the lines
+   `SECRETS.local.md` and `*.local.patch` (create or append as needed —
+   the patch pattern is used by `/modernize-harden`; writing both now
+   means the ignore set is complete from first contact). If the project is a
    git repo, verify with `git check-ignore -q analysis/$1/SECRETS.local.md`
    — do not write any findings until the check passes. If there is **no
    git repo** (check for `.svn`/`.hg`/`CVS` too — a `.gitignore` protects