You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
.dockerignore:1-2 only excludes node_modules and npm-debug.log.
docker/Dockerfile:23 and docker/Dockerfile.dev:26 both use ADD . /home/node/app.
Current ignored local files include .env, .agents/, .crush/, .nyc_output/, coverage/, docker/.docker-env, test-http/docker/.docker-env, Python cache directories, .DS_Store, and src/scripts/export.xlsx.
Current local artifact sizes include coverage at about 119 MB and .nyc_output at about 1.9 MB.
Impact:
Local Docker builds can copy ignored local secrets and generated artifacts into the build context and possibly the image.
Build context size is larger than necessary.
Production and dev images depend on the state of a developer workstation, not just tracked source.
Recommendation:
Expand .dockerignore to mirror relevant .gitignore entries: .env, .env.*, .git, .agents, .crush, .vscode, coverage, .nyc_output, .DS_Store, **/__pycache__, **/.pytest_cache, **/*.pyc, test-http/src/testOutput.txt, docker/.docker-env, test-http/docker/.docker-env, src/scripts/export.xlsx, user-secret.txt, and similar local-only outputs.
Prefer explicit COPY steps in production Dockerfile: package manifests first, install with npm ci --omit=dev, then copy only runtime directories/files (src, schemas, api-docs, config, docker/entrypoint.sh, etc.).
Evidence:
.dockerignore:1-2only excludesnode_modulesandnpm-debug.log.docker/Dockerfile:23anddocker/Dockerfile.dev:26both useADD . /home/node/app..env,.agents/,.crush/,.nyc_output/,coverage/,docker/.docker-env,test-http/docker/.docker-env, Python cache directories,.DS_Store, andsrc/scripts/export.xlsx.coverageat about 119 MB and.nyc_outputat about 1.9 MB.Impact:
Recommendation:
.dockerignoreto mirror relevant.gitignoreentries:.env,.env.*,.git,.agents,.crush,.vscode,coverage,.nyc_output,.DS_Store,**/__pycache__,**/.pytest_cache,**/*.pyc,test-http/src/testOutput.txt,docker/.docker-env,test-http/docker/.docker-env,src/scripts/export.xlsx,user-secret.txt, and similar local-only outputs.COPYsteps in production Dockerfile: package manifests first, install withnpm ci --omit=dev, then copy only runtime directories/files (src,schemas,api-docs,config,docker/entrypoint.sh, etc.).