diff --git a/CHANGELOG.md b/CHANGELOG.md index d352048..0088e34 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,17 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). ## Unreleased +### Added + +- **Seeded global gitignore now ignores `**/.claude/settings.local.json`.** Claude + Code's per-machine local settings file holds machine-specific permissions and + can carry credentials, so it should never be committed. The seed + (`rootfs/home/developer/.gitignore_global`, baked to `/etc/skel-devbox/`) gains + the pattern so fresh containers match a host global that already ignores it. + Existing containers are unaffected (the seed is copied only when + `~/.gitignore_global` is absent); their file can be updated by hand. Base- + affecting (`Dockerfile.base` COPY of the seed), rebuilds `base-`. + ### Fixed - **`pandoc --pdf-engine=typst` now works without `-V mainfont`.** pandoc's diff --git a/rootfs/home/developer/.gitignore_global b/rootfs/home/developer/.gitignore_global index c35a754..9452b8b 100644 --- a/rootfs/home/developer/.gitignore_global +++ b/rootfs/home/developer/.gitignore_global @@ -9,3 +9,6 @@ *.orig *.swp *.tmp + +# AI/LLM tool local settings — machine-specific perms + credentials, never commit +**/.claude/settings.local.json