Files
EJClaw/.gitignore
Codex c016b9c2fa port: apply 7 upstream security/robustness patches
Ports from isolated upstream-port branch (base b3c5a4b), verified in
isolation via baseline-vs-port failure-set diff and re-verified live
(195 pass / 0 fail on affected tests):
- redact Discord bot tokens in outbound (router.ts SECRET_PATTERNS)
- block SSRF to private hosts in MoA base URL (moa.ts)
- refuse public dashboard bind without auth token (web-dashboard-server.ts)
- merge upstream .gitignore rules for python/build/secret noise
- real CPU utilization from /proc/stat instead of load avg (unified-dashboard.ts)
- width-safe placeholder for missing usage window on mobile (unified-dashboard.ts)
- bump direct deps to patch known vulnerabilities (discord.js/yaml/cron-parser)

Risky upstream commits (d5a94af phantom reset-time, patch 6 Codex usage)
intentionally skipped to avoid touching the credential-isolation tree.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-24 19:35:59 +09:00

75 lines
958 B
Plaintext

# Dependencies
node_modules/
.npm-cache/
# Build output
dist/
runners/*/dist/
apps/android/.gradle/
apps/android/build/
apps/android/app/build/
apps/android/local.properties
# Local data & auth
store/
store-*/
data/
data-*/
logs/
.ejclaw-reviewer-runtime/
# Groups - only track base structure and specific CLAUDE.md files
groups-*/
groups/*
!groups/main/
!groups/global/
groups/main/*
groups/global/*
!groups/main/CLAUDE.md
!groups/global/CLAUDE.md
# Secrets
*.keys.json
.env
.env.codex
.env.minimax
# Temp files
.tmp-*
tmp/
backups/
dist-backups/
.deploy-backups/
recovery/
cache/
runners/*/node_modules/
runners/codex-runner-backups/
*.bak-*
# OS
.DS_Store
._*
# IDE
.idea/
.vscode/
agents-sdk-docs
# --- merged from upstream 048a89d (python/node/build/secret noise) ---
build/
.bun-cache/
.DS_Store
*.egg-info/
.env
!.env.example
__pycache__/
*.py[cod]
.pytest_cache/
*.sqlite
*.sqlite-journal
*.sqlite-shm
*.sqlite-wal
*.swp
*.tsbuildinfo
.venv/