Skip to content

feat(templates): scaffold a .gitignore that excludes .env and .venv - #513

Open
michaelxu2288 wants to merge 2 commits into
scaleapi:mainfrom
michaelxu2288:feat/templates-gitignore
Open

michaelxu2288 wants to merge 2 commits into
scaleapi:mainfrom
michaelxu2288:feat/templates-gitignore

Conversation

@michaelxu2288

@michaelxu2288 michaelxu2288 commented Sep 10, 2026 •

Copy link
Copy Markdown

What

agentex init writes .env.example and tells users to create .env with an API key. .dockerignore protects the image build, but no template ships a .gitignore, so git init && git add . in a scaffolded folder commits .env (and .venv). Adds a .gitignore.j2 to all 19 templates (secrets, Python artifacts, tool caches; .env.example stays committable), registers it in root_templates in commands/init.py, and adds a parametrized test asserting every scaffold renders it with .env and .venv/ excluded.

Test

tests/lib/cli/test_init_templates.py: 45 passed (26 existing + 19 new). ruff clean.

RetriggerConfidence Score: 4/5

The PR is not ready to merge while rerunning agentex init can make .env.example ignored.

Fix All in CursorFindings

  1. P1 Gitignore Rule Order Breaks ▶
Fix with agent prompt
### Issue 1
src/agentex/lib/cli/commands/init.py:127-129
When an existing `.gitignore` already contains `!.env.example` but does not contain `.env.*`, this order-insensitive check skips the existing negation and appends `.env.*` after it. Git uses the last matching rule, so rerunning `agentex init` then ignores `.env.example` even though the scaffold promises that the example file remains committable. Preserve the template rules as an ordered block or otherwise account for their effective order when merging.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR adds .gitignore files to all 19 agentex init templates and makes task creation wait for its workflow to start. It also updates release and CI automation for a main-only production flow, adds security scan workflows, and points production clients at the hosted Agentex service.

  • Keeps .env.example shareable while excluding local secrets, virtual environments, and Python tool files.
  • Creates the GitHub release before opening the next release pull request, and updates guidance and workflows for main.
  • Adds OpenGrep, TruffleHog, and Bandit workflow entry points.

Reviews (3) · Last reviewed commit: "fix(init): merge scaffold entries into a..."

Comment thread src/agentex/lib/cli/commands/init.py
Comment on lines +127 to +129
existing_lines = {line.strip() for line in existing.splitlines()}
missing = [line for line in rendered.splitlines() if line.strip() and not line.startswith("#") and line.strip() not in existing_lines]
if missing:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Gitignore Rule Order Breaks

When an existing .gitignore already contains !.env.example but does not contain .env.*, this order-insensitive check skips the existing negation and appends .env.* after it. Git uses the last matching rule, so rerunning agentex init then ignores .env.example even though the scaffold promises that the example file remains committable. Preserve the template rules as an ordered block or otherwise account for their effective order when merging.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/agentex/lib/cli/commands/init.py
Line: 127-129

Comment:
**Gitignore Rule Order Breaks**

When an existing `.gitignore` already contains `!.env.example` but does not contain `.env.*`, this order-insensitive check skips the existing negation and appends `.env.*` after it. Git uses the last matching rule, so rerunning `agentex init` then ignores `.env.example` even though the scaffold promises that the example file remains committable. Preserve the template rules as an ordered block or otherwise account for their effective order when merging.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

@stainless-app
stainless-app Bot force-pushed the next branch 2 times, most recently from bc51c52 to 761833e Compare September 18, 2026 21:47
agentex init writes an .env.example and tells users to create .env with
their API key, and the Dockerfile path is protected by .dockerignore, but no
template ships a .gitignore. A user who git-inits the scaffolded folder
commits .env (and .venv) on the first add. Add a .gitignore to every
template (secrets, Python artifacts, tool caches; .env.example stays
committable) and a test asserting each scaffold renders it.

Claude-Session: https://claude.ai/code/session_01HCVKnA7LeJZ44nxZz1uzF3
… of overwriting it

Re-running agentex init on an existing project replaced the user's
.gitignore. Keep the existing file and append only the scaffold entries that
are missing, with a test for the merge.

Claude-Session: https://claude.ai/code/session_01HCVKnA7LeJZ44nxZz1uzF3
@michaelxu2288
michaelxu2288 force-pushed the feat/templates-gitignore branch from 837f57f to 1df5a34 Compare October 1, 2026 09:40
@michaelxu2288
michaelxu2288 changed the base branch from next to main October 1, 2026 09:40
@greptile-apps

greptile-apps Bot commented Oct 1, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings could not be posted inline.

  • P2 Bandit findings stay hidden .github/workflows/bandit-ci.yml:91 ▶

    When the reporting endpoint is unset, this job says Bandit's findings are in the log. Both scans write to JSON files instead, and the job never prints or uploads them. Reviewers cannot see the findings even though the job passes. Print or upload the results when reporting is unavailable.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant