commit 085c6978883ed2756dc2cfe865362b0d5edc96b6
parent 4659a54b185f56e5742749099c8751d74e1a6df8
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Tue, 6 Oct 2026 08:56:50 -0400
docs: RUNNING_IN_DOCKER — the image has no gitleaks or stagit, so a container's source publish skips the secret scan (with its warning) and the history pages
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/RUNNING_IN_DOCKER.md b/RUNNING_IN_DOCKER.md
@@ -288,7 +288,13 @@ docker compose cp ~/.config/archilyzer/source-denylist.txt editor:/data/config/a
docker compose exec editor chmod 600 /data/config/archilyzer/source-scrub.txt /data/config/archilyzer/source-denylist.txt
```
-`git-filter-repo` (pinned) is in the image.
+`git-filter-repo` (pinned) is in the image. **gitleaks and stagit are not**, so a
+source publish from the container is weaker than a host's in two ways it tells you
+about: it skips the secret scan, with a `WARNING` in its log (the literal audit
+against your denylist still runs, and still refuses), and it publishes the source
+without its history pages (`/source/git/`). `archilyzer doctor` lists both as
+absent. Publish the mirror from a host checkout that has them if you want either;
+a pinned gitleaks in the image is a planned follow-up.
### Model choice