mirror of
https://github.com/MadsLorentzen/ai-job-search.git
synced 2026-09-17 00:26:26 +00:00
/add-portal can generate a skill for a portal that only returns usable
content through a paid fetching service, and such a skill reads its API
token from the environment. Nothing stopped the `.env` holding that token
from being committed: `.gitignore` had no `.env` rule, and
`REQUIRED_IGNORE_RULES` in tools/security_guards.py did not pin one.
No shipped portal needs a credential - all six are free and
unauthenticated - so upstream has never hit this. A fork whose generated
portals do need one hits it on the first `git add -A`.
Add `.env` and `.env.*` to `.gitignore`, and pin both in
`REQUIRED_IGNORE_RULES` so the guard fails if the rule is later dropped.
No negation rule is added, so `ALLOWED_IGNORE_NEGATIONS` is untouched.
Verified:
- `printf 'X=y' > .env && git check-ignore -v .env` -> matched
- dropping the `.env` line makes `python3 tools/security_guards.py`
report the missing rule and fail; restoring it returns OK
- `lint_skills`, `check_framework_version`, `security_guards` all OK;
`python3 -m unittest discover -s tests` 196 passed
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
103 lines
2.5 KiB
Plaintext
103 lines
2.5 KiB
Plaintext
# Dependencies
|
|
node_modules/
|
|
bun.lock
|
|
|
|
# Python
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
.venv/
|
|
venv/
|
|
|
|
# Compiled documents
|
|
*.pdf
|
|
*.aux
|
|
*.log
|
|
*.out
|
|
*.synctex.gz
|
|
*.fls
|
|
*.fdb_latexmk
|
|
|
|
# Personal data (never commit these)
|
|
salary_data.json
|
|
# Match at any depth: the job-scraper skill resolves `job_scraper/` relative to
|
|
# its own directory, so these land at .claude/skills/job-scraper/job_scraper/*.
|
|
# A rooted `job_scraper/...` pattern silently fails to match them.
|
|
**/job_scraper/seen_jobs.json
|
|
**/job_scraper/notion_sync.json
|
|
**/job_scraper/*.md
|
|
*_BehavioralReport.pdf
|
|
linkedin_Profile.pdf
|
|
|
|
# Secrets. A portal skill generated by /add-portal may need an API token for a
|
|
# fetching service; the .env holding it must never be committed.
|
|
.env
|
|
.env.*
|
|
|
|
# Personal photos and signatures
|
|
*.jpg
|
|
*.jpeg
|
|
*.png
|
|
!cover_letters/OpenFonts/fonts/**
|
|
|
|
# OS files
|
|
.DS_Store
|
|
Thumbs.db
|
|
|
|
# Editor
|
|
.vscode/
|
|
.idea/
|
|
|
|
# Memory files (Claude Code user-specific)
|
|
.claude/projects/
|
|
|
|
# Skills lock (auto-generated)
|
|
skills-lock.json
|
|
|
|
# Personal application output files (generated by /apply — do not share)
|
|
# Extension-agnostic on the ignore side: a custom template registered via
|
|
# /add-template (e.g. Typst) writes main_<company>_<role>.typ instead of
|
|
# .tex, and it must be ignored just as reliably as the stock LaTeX output.
|
|
# The negations stay .tex-only - the stock example files are always LaTeX,
|
|
# and a wildcard negation (!cv/main_example.*) would also re-include build
|
|
# artifacts like main_example.pdf/.aux.
|
|
cv/main_*.*
|
|
!cv/main_example.tex
|
|
cv/*.txt
|
|
cover_letters/cover_*.*
|
|
cover_letters/Cover_*.*
|
|
!cover_letters/cover_example.tex
|
|
|
|
# documents/ subfolder contents are personal — only README and folder structure are tracked
|
|
documents/cv/**
|
|
documents/linkedin/**
|
|
documents/diplomas/**
|
|
documents/references/**
|
|
documents/applications/**
|
|
documents/postings/**
|
|
# Interview prep and experience records: these name the employers applied to,
|
|
# quote what was submitted, and set out the candidate's weak points.
|
|
documents/interview/**
|
|
!documents/**/.gitkeep
|
|
|
|
# Personal job search tracking
|
|
job_search_tracker.csv
|
|
|
|
# Gmail sync state (message IDs, subjects - personal data)
|
|
gmail_sync/
|
|
|
|
# Generated reports (personal output from /html-report)
|
|
reports/
|
|
|
|
# Upskill reports (personal output)
|
|
upskill/*.md
|
|
|
|
# Agent skills: track the source, ignore only deps and logs.
|
|
# (A blanket `.agents/` ignore silently drops the job-search CLI skills from the repo.)
|
|
.agents/**/node_modules/
|
|
.agents/**/*.log
|
|
.agents/usage/
|
|
|
|
# Brainstorm mockups (superpowers visual companion) - never ship
|
|
.superpowers/
|