You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Risk of committing it. An agent doing git add -A after a build can sweep the
rebuilt binary into an unrelated PR, replacing the committed artifact with one built on
the agent's machine. That is a supply-chain-relevant change, not a cosmetic one.
Noise in review and blame. Binary diffs are unreviewable and the file is dead weight
in the history.
Proposal
git rm --cached the binary from the tree.
Add the exact path to .gitignore.
No coordination needed — verified already: nothing copies the committed artifact. The
Dockerfile builds the binary inside the image and copies it across from the builder stage.
The committed blob is unreferenced. Removing it from the tree is safe and reversible.
Notes
The binary is currently in the history; removing it from the tree does not rewrite history.
A follow-up decision on history rewriting is separate and out of scope.
Problem
A compiled Go binary is committed and tracked in git:
Verified on
main:Impact
Any
go buildrun in-tree — by a human, a delegated agent, or a local verification step —silently rewrites the tracked blob. Consequences:
git statusafter a local build shows a modified binary that hasnothing to do with the change under review. During the feat(http-honeypot): measure #3394's Ollure coverage and add the model-target class #3442 conflict resolution this
produced exactly that: a dirty worktree that had to be restored by hand.
git add -Aafter a build can sweep therebuilt binary into an unrelated PR, replacing the committed artifact with one built on
the agent's machine. That is a supply-chain-relevant change, not a cosmetic one.
in the history.
Proposal
git rm --cachedthe binary from the tree..gitignore.Dockerfile builds the binary inside the image and copies it across from the builder stage.
Verified on
main:The committed blob is unreferenced. Removing it from the tree is safe and reversible.
Notes
A follow-up decision on history rewriting is separate and out of scope.
main.goclassifier merge conflict on feat(http-honeypot): measure #3394's Ollure coverage and add the model-target class #3442. Not caused bythat PR — pre-existing.