ci(pr-proof): treat top-level repo metadata as non-runtime (#1647)
* ci(pr-proof): treat top-level repo metadata as non-runtime The gate refused a PR whose only extra file was .gitignore, because an unlisted path counts as runtime. That is the allowlist working as designed, but .gitignore cannot change what an installed CLI or broker does, so it is a genuine gap rather than a gate defect. .gitignore, .gitattributes and .editorconfig are now listed. They are listed individually rather than as a dotfile glob on purpose: a top-level dotfile that DOES affect what gets built or installed — an .npmrc or .nvmrc — must keep demanding a proof. A glob would have exempted those too. Tests: 87 passing, 6 skipped. Two mutations checked — removing the entries turns the metadata test red, and widening them to a dotfile glob turns the .npmrc guard red. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014N3p9VEngj9kLDFFhrzHNd Session-Id: 246fba6e-6436-46ae-bc50-6bb3cca0d95e * ci(pr-proof): drop .gitattributes from the metadata exemption Review pushed back on exempting .gitignore, and checking the claim properly turned up a sharper problem with a neighbour I had added by association. .gitattributes is now NOT exempt. `export-ignore` removes files from `git archive`, and .github/workflows/relayflow-pr-proof-broker.yml builds its isolated source tree with exactly that command, so a .gitattributes edit can change what a proof compiles against. `text`/`eol` normalisation can also change file contents. That is a different class from "which files git tracks" and I grouped it in without thinking it through. .gitignore stays, for reasons that are checkable rather than assumed: - every published package declares an explicit `files` array, so npm never falls back to .gitignore for packaging - the shipped consumer of a .gitignore, buildIgnoreMatcher in packages/cloud/src/workflows.ts, reads the USER's project root, not this repo's, so editing this file cannot change what an installed agent-relay does in someone else's project Its only remaining reach is this repo's own cloud tarball, which is the same CI scope already exempted through workflows/ and .github/. Tests: 88 passing, 6 skipped, including a new guard asserting .gitattributes is treated as runtime. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014N3p9VEngj9kLDFFhrzHNd Session-Id: 246fba6e-6436-46ae-bc50-6bb3cca0d95e --------- Co-authored-by: Proactive Runtime Bot <agent@agent-relay.com>
K
Khaliq committed
6eefb3cd77877b96713033066bd221d75cbe539c
Parent: 7320d32
Committed by GitHub <noreply@github.com>
on 9/2/2026, 8:05:40 PM