chore: clean up repository configuration, ignore rules and docs - #106
Merged
Merged
Conversation
Existing checkouts keep an untracked "ressources/" directory holding the gitignored RNGdle JSON tables; they are regenerated under "resources/" and the old directory can be deleted by hand. Docker deployments are unaffected: the folder ships inside the image, not on a volume.
@Lindwen wants to use dependabot for its GitHub integration. We don't want to use both renovatebot & dependabot so renovate must go.
Group rules by domain instead of by file type, and add owners for the RNGdle module, the privacy policy and the design assets. CODEOWNERS does not merge matching rules, the last one wins: the catch-all @gamingdy is therefore intentionally dropped on paths that have a more specific owner (Dockerfile, compose.prod.yaml, PRIVACY.md).
The organisation was renamed to GravenDev, the project now requires Python 3.13, the docker-compose V1 CLI is gone, and @AntoineJT was missing from the collaborators.
AntoineJT
requested review from
Alessevan,
Lindwen and
gamingdy
as code owners
September 16, 2026 23:22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🇬🇧 English
🎯 Summary
Housekeeping over the repository configuration: ignore rules, CODEOWNERS, environment-variable documentation and the README. No runtime change — the only source edit is the
ressources/→resources/rename and the paths that follow it.🤔 Motivation
Three problems the diff alone doesn't reveal.
.env.prodwas neither gitignored nor docker-ignored..gitignoreonly matched*.env, which does not match.env.prod, and theDockerfiledoesCOPY ./ /app. Creating a.env.prodfrom the example and building locally would have committed the token, or shipped it in an image published on ghcr.io.I audited the three most recent published images (
1.5.1,1.5.0,1.4.19):/app/.env.prodis present in all three but empty, and a scan of/appfinds no Discord token pattern and no non-empty secret assignment. No secret has ever leaked — CI builds from a clean checkout, so the gap was reachable only from a local build. This is preventive hardening, not an incident response.Two CODEOWNERS rules matched nothing.
resources/*andalembic/*do not cross directory boundaries, so every asset underresources/font/,resources/images/andresources/rngdle/was unowned while appearing to be covered..env.examplewas unsafe to copy. It documented 2 of the 6 variables read byconfig.py, andDEBUG_GUILD_ID=was empty — so copying it verbatim, exactly as the README instructed, makesconfig.pyraiseValueError: DEBUG_GUILD_ID must be an integer representing a guild ID.at import, for a variable documented as optional.📦 What's included
.gitignoreand.dockerignorenow cover the same ground; the published image no longer carries environment files, repository metadata or local bytecode..env.examplebecomes the single reference for the six variables; the README points to it instead of duplicating it — the duplicate had already drifted.renovate.jsonremoved. The app itself was offboarded from the repository outside this PR and its open PRs closed — deleting the file alone would have changed nothing. Dependabot already covers the same ecosystems..dockerignore, and a scan of the exported filesystem confirms the exclusions take effect while every file the runtime needs is still present.🧭 Notes
@gamingdyis therefore intentionally dropped on paths that have a more specific owner (Dockerfile,compose.prod.yaml,PRIVACY.md).ressources/directory holding the gitignored RNGdle JSON tables. They are regenerated underresources/and the old directory can be deleted by hand. Docker deployments are unaffected: the folder ships inside the image, not on a volume.🇫🇷 Français
🎯 Résumé
Ménage sur la configuration du dépôt : règles d'ignore, CODEOWNERS, documentation des variables d'environnement et README. Aucun changement à l'exécution — la seule modification de source est le renommage
ressources/→resources/et les chemins qui en découlent.🤔 Motivation
Trois problèmes que le diff seul ne révèle pas.
.env.prodn'était ignoré ni par git ni par Docker..gitignorene contenait que*.env, qui ne correspond pas à.env.prod, et leDockerfilefaitCOPY ./ /app. Créer un.env.prodà partir de l'exemple puis builder en local aurait commité le token, ou l'aurait embarqué dans une image publiée sur ghcr.io.J'ai audité les trois dernières images publiées (
1.5.1,1.5.0,1.4.19) :/app/.env.prodest présent dans les trois mais vide, et un scan de/appne trouve aucun motif de token Discord ni aucune affectation de secret non vide. Aucun secret n'a jamais fuité — la CI build depuis un checkout vierge, le trou n'était donc atteignable que depuis un build local. Il s'agit d'un durcissement préventif, pas d'une réponse à incident.Deux règles CODEOWNERS ne correspondaient à rien.
resources/*etalembic/*ne traversent pas les frontières de répertoire : chaque asset sousresources/font/,resources/images/etresources/rngdle/était sans propriétaire tout en paraissant couvert..env.exampleétait dangereux à copier. Il documentait 2 des 6 variables lues parconfig.py, etDEBUG_GUILD_ID=était vide — le copier tel quel, exactement comme le README l'indiquait, fait lever àconfig.pyunValueError: DEBUG_GUILD_ID must be an integer representing a guild ID.à l'import, pour une variable documentée comme optionnelle.📦 Contenu
.gitignoreet.dockerignorecouvrent désormais le même périmètre ; l'image publiée n'embarque plus de fichiers d'environnement, de métadonnées de dépôt ni de bytecode local..env.exampledevient la référence unique des six variables ; le README pointe dessus au lieu de la dupliquer — le doublon en avait déjà divergé.renovate.jsonsupprimé. L'app elle-même a été retirée du dépôt hors de cette MR et ses PR ouvertes fermées — supprimer le fichier seul n'aurait rien changé. Dependabot couvre déjà les mêmes écosystèmes..dockerignore, et un scan du système de fichiers exporté confirme que les exclusions prennent effet tandis que tout ce dont l'exécution a besoin est toujours présent.🧭 À noter
@gamingdyest donc volontairement abandonné sur les chemins ayant un propriétaire plus spécifique (Dockerfile,compose.prod.yaml,PRIVACY.md).ressources/non suivi contenant les tables JSON RNGdle gitignorées. Elles sont régénérées sousresources/et l'ancien répertoire peut être supprimé à la main. Les déploiements Docker ne sont pas concernés : le dossier voyage dans l'image, pas sur un volume.