Skip to content

fix(gitignore): ignore .claude/ so the rule travels with the repo (#1266) - #1273

Open
prx-my wants to merge 2 commits into
OWASP:mainfrom
prx-my:fix/issue-1266-gitignore-claude
Open

prx-my wants to merge 2 commits into
OWASP:mainfrom
prx-my:fix/issue-1266-gitignore-claude

Conversation

@prx-my

@prx-my prx-my commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

What changed and why

.claude/ was not in .gitignore. It was kept out only by a machine-local
.git/info/exclude, which is not version-controlled and does not travel with a
clone, so a fresh clone had no protection. Add .claude/ alongside the existing
.superpowers/ and docs/superpowers/ entries (.gitignore:22).

Verification

Ignoring is confirmed against .gitignore itself, with machine-local excludes
bypassed, so a broken pattern can't be masked:

$ git -c core.excludesfile=/dev/null check-ignore -v --no-index .claude/settings.local.json
.gitignore:22:.claude/	.claude/settings.local.json

Holds for the other paths and for a nested path:

$ git -c core.excludesfile=/dev/null check-ignore -v --no-index .claude/agents/x.md .claude/skills/y/SKILL.md
.gitignore:22:.claude/	.claude/agents/x.md
.gitignore:22:.claude/	.claude/skills/y/SKILL.md

No tracked file becomes ignored — still exactly the 9 pre-existing fixtures:

$ git ls-files -i -c --exclude-standard | wc -l
9

No .claude/ file is tracked:

$ git ls-files | grep '^\.claude/' | wc -l
0

Note: the issue suggests check-ignore --exclude-from=.gitignore, but that flag
is not a git check-ignore option (it belongs to git ls-files); on git 2.54 it
exits 129. The -c core.excludesfile=/dev/null check-ignore -v above achieves the
same intent and names the matching source.

Closes #1266

@prx-my
prx-my requested a review from sonukapoor as a code owner October 3, 2026 11:00
Copilot AI balanced review requested due to automatic review settings October 3, 2026 11:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

@prx-my

prx-my commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Update: this branch has been refreshed with the latest main. It is no longer behind and now only awaits the required review/status checks before it can merge.

@prx-my
prx-my force-pushed the fix/issue-1266-gitignore-claude branch from 34b463c to f3726c2 Compare October 8, 2026 11:47
…ASP#1266)

.claude/ was kept out only by a machine-local .git/info/exclude, which does not travel with a clone. Add it alongside .superpowers/ and docs/superpowers/ so a fresh clone has the protection.

Verified: git check-ignore -v names .gitignore:22:.claude/ for top-level and nested paths; git ls-files -i -c --exclude-standard still returns exactly the 9 pre-existing examples/*/node_modules/*/package.json fixtures; no .claude/ file is tracked.

@sonukapoor sonukapoor left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this, and the reasoning in the description is the right one: the rule belongs in the repo rather than in each person's global excludes, so nobody has to remember it.

On your branch .claude/settings.json, .claude/skills/foo/SKILL.md and a nested nested/.claude/settings.json are all ignored; on main none of them are. It does not over-reach, so .claudeignore is untouched. And nothing under .claude/ is tracked today, so no file silently drops out of the index when this lands.

One thing worth noting that makes the case stronger than the description claims: cve-lite install-skill writes into .claude/commands/, so this also stops a dogfooded run of our own command leaving untracked output that someone could commit by accident.

The one thing I want before it goes in is a test. tests/gitignore.test.ts has an it.each table of paths that must be ignored, and there is no .claude entry in it, so deleting the line you are adding leaves all 13 tests in that file green. Two strings in that array does it, and the existing entries already pair a root path with a nested one:

".claude/settings.json",
"nested/.claude/settings.json",

That turns the pattern from present into pinned, which is the whole point of putting it in the repo.

@prx-my

prx-my commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Thanks @sonukapoor — added both entries to the it.each table in tests/gitignore.test.ts:

  • .claude/settings.json
  • nested/.claude/settings.json

Pinned, not just present: reverting .gitignore to main makes exactly those two cases fail, and with the line back all 15 tests in the file pass. npm run lint:tests is green. Pushed as 491acd6 — re-requesting review.

@prx-my
prx-my requested a review from sonukapoor October 9, 2026 21:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(gitignore): .claude/ is not ignored, only a machine-local exclude keeps it out

3 participants