fix(privacy): ignore scraper state and interview records at any depth (#208)

job_scraper/seen_jobs.json (and notion_sync.json / *.md) were ignored by a repo-rooted pattern, but the job-scraper skill resolves job_scraper/ relative to its own directory, so the state file lands at .claude/skills/job-scraper/job_scraper/ and the rule never matched - publishing every scraped posting with fit scores and skip-reasons on a public fork. Switches to **/-prefixed patterns that match at any depth (the rooted location still matches too, so no regression), and adds documents/interview/** (interview prep names employers, quotes submitted material, and lists the candidate's weak points) - it was never ignored though documents/applications/** was. REQUIRED_IGNORE_RULES updated in lockstep so the security guard stays in sync.

By @LeoWinston-9596 (split from #199). Verified: both nested and root seen_jobs.json now ignored, interview records ignored, guard suite green (17 tests incl. #195's negation checks). Rebased cleanly on current master.
This commit is contained in:
LeoWinston-9596
2026-07-21 07:39:56 +02:00
committed by GitHub
parent 3d8689a56d
commit 808be3daad
2 changed files with 14 additions and 4 deletions
+5 -1
View File
@@ -44,7 +44,10 @@ ALLOWED_PERMISSIONS = {
# Personal-data ignore rules that must never disappear from .gitignore.
REQUIRED_IGNORE_RULES = [
"salary_data.json",
"job_scraper/seen_jobs.json",
# Depth-independent: the job-scraper skill resolves `job_scraper/` relative
# to its own directory, so the state file lands under .claude/skills/... and
# a repo-rooted rule silently fails to match it.
"**/job_scraper/seen_jobs.json",
"cv/main_*.tex",
"!cv/main_example.tex",
"cover_letters/cover_*.tex",
@@ -53,6 +56,7 @@ REQUIRED_IGNORE_RULES = [
"documents/diplomas/**",
"documents/references/**",
"documents/applications/**",
"documents/interview/**",
"job_search_tracker.csv",
]