gitattributes

Verwenden Sie beim Prüfen oder Aktualisieren der .gitattributes export-ignore-Abdeckung, damit entwicklerspezifische Dateien (Lint-Konfigurationen, CI, Tests, Dokumentation, Build-Tools) nicht im…

npx skills add https://github.com/automattic/wordpress-activitypub --skill gitattributes

.gitattributes Export-Ignore Audit

Ensure the WordPress.org release archive (git archive output) contains only runtime files. Dev tooling, tests, CI, and repo meta must be export-ignored.

Why This Matters

The WordPress.org zip is built via git archive. Anything without export-ignore ends up on every user's site, bloating the install and shipping dev-only code. Equally bad: stale export-ignore entries for files that no longer exist look tidy but protect nothing.

Quick Audit (one command)

# Entries in the release archive at the repository root
git archive --format=tar HEAD | tar -t | awk -F/ '{print $1}' | sort -u

# Same, but uses the working-tree .gitattributes (use while iterating on edits)
git archive --worktree-attributes --format=tar HEAD | tar -t | awk -F/ '{print $1}' | sort -u

git archive HEAD reads .gitattributes from the commit, so uncommitted fixes won't show up. Use --worktree-attributes to preview a pending change before committing.

The output should contain ONLY runtime artifacts. For this plugin that's: LICENSE, readme.txt, activitypub.php, assets, build, includes, integration, patterns, templates.

Anything else in the list is a gap — add an export-ignore rule.

Cross-Check Tracked vs Ignored

# Top-level tracked entries
git ls-tree --name-only HEAD | sort > /tmp/tracked.txt

# Entries referenced in .gitattributes
grep export-ignore .gitattributes | awk '{print $1}' | sed 's|^/||; s|/$||' | sort > /tmp/ignored.txt

# Stale entries (in .gitattributes but no longer tracked)
comm -23 /tmp/ignored.txt /tmp/tracked.txt

Stale entries aren't dangerous, but they rot and mislead future readers. Delete them.

What Belongs in Each Bucket

CategoryExamplesRule
Runtime PHPactivitypub.php, includes/, integration/keep
Runtime assetsassets/, build/, patterns/, templates/keep
WordPress.org metareadme.txt, LICENSEkeep
Dev dotfiles.editorconfig, .prettierrc.js, .stylelintrc.json, eslint.config.cjs, .wp-env.jsonexport-ignore
Repo meta.github/, .githooks/, .gitignore, .gitattributes, .wordpress-org/export-ignore
Agent/AI tooling.agents/, .claude/, AGENTS.md, CLAUDE.mdexport-ignore
Build & package configspackage.json, package-lock.json, composer.json, webpack.config.js, tsconfig.json, jest.config.js, jest.setup.jsexport-ignore
QA configsphpcs.xml, phpunit.xml.distexport-ignore
Source (pre-build)src/export-ignore (shipping build/ instead)
Teststests/export-ignore
Docs for contributorsdocs/, snippets/, CHANGELOG.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, FEDERATION.md, README.md, SECURITY.mdexport-ignore
Scriptsbin/, local/export-ignore

When to Run This Audit

  • Before tagging a release.
  • After adding or renaming any top-level file, dotfile, or config.
  • After adopting a new dev tool (lint, test runner, bundler).
  • When a linter flat-config migration renames files (e.g. .eslintrc.js → eslint.config.cjs).

Writing Rules

  • Use a leading / to anchor to the repo root: /phpcs.xml, not phpcs.xml.
  • Use a trailing / for directories: /tests/.
  • Keep grouping comments tidy (dotfiles, build configs, source/tests, docs, linguist).

Linguist Attributes (bonus)

Also used in .gitattributes to shape GitHub's language stats:

  • /build/** linguist-generated — hides machine-built output.
  • /docs/** linguist-documentation — keeps docs out of the language bar.
  • /package-lock.json linguist-generated — hides lockfile churn.

These don't affect the archive, but live in the same file, so keep them current too.

Red Flags

  • Release zip is larger than expected → something new is leaking in.
  • New dev dependency added, .gitattributes untouched → likely a gap.
  • Lint tool migrated to a new config filename → old entry is stale, new file is leaking.
  • Top-level file renamed → old export-ignore is dead weight, new one is missing.

Mehr Skills von automattic

testing-js
automattic
Richtlinien zur Überprüfung von JavaScript-Dateien auf Syntaxfehler
setup
automattic
Überprüfen, ob die dn CLI installiert und konfiguriert ist. Verwenden, wenn der Benutzer das domain-names Plugin zum ersten Mal installiert oder wenn ein dn-Befehl fehlschlägt, weil die CLI nicht…
studio-cli
automattic
Verwenden Sie die Studio-CLI, um lokale WordPress-Seiten, Authentifizierung und Vorschauseiten zu verwalten. Rufen Sie diese Fähigkeit auf, wenn Sie Studio-CLI-Befehle ausführen, verwalten…
dn-info
automattic
Holen Sie detaillierte Informationen über eine registrierte Domain mit der dn CLI. Verwenden Sie dies, wenn der Benutzer Domaindetails wie Ablaufdatum, Nameserver, Kontakte usw. sehen möchte.
qa
automattic
Extrahierte WXR-Inhalte Seite für Seite mit der ursprünglichen Quellseite vergleichen. Fehlende Texte, Überschriften, Bilder und Links finden. Durch Patchen der WXR-Datei beheben oder…
add-skill
automattic
Füge einen neuen Skill zum a8c-design-Plugin hinzu. Verwende dies, wenn du einen Claude Code Skill erstellt hast und ihn zum gemeinsamen Automattic a8c-design-Plugin beitragen möchtest —…
design-foundations
automattic
Erstelle ein kohärentes Design-Foundation-JSON aus einer befreiten Website – semantische Farb-/Typografie-/Abstandsrollen mit Evidenzpfaden. Konsumiert das partielle Gerüst…
wp-phpstan
automattic
Verwenden beim Konfigurieren, Ausführen oder Beheben von PHPStan-Statikanalysen in WordPress-Projekten (Plugins/Themes/Websites): phpstan.neon-Setup, Baselines,…