Conversation
Block Read access to project-level secrets (.env files, private keys, credentials, blockchain keystores/mnemonics, Terraform/Ansible/k8s state) via permissions.deny rules instead of .claudeignore (not an official feature). Document the approach in the sandboxing section of the README. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Based on trailofbits/claude-code-devcontainer. Adds Go 1.23 + golangci-lint, gofumpt, govulncheck for Story/Cosmos SDK work. Replaces the single-link devcontainer section in README with step-by-step instructions for CLI, VS Code/Cursor, and shared workspace usage. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Bakes personas/ and scripts/ into the Docker image. The PERSONA env var (default: developer) controls which persona post_install.py copies into ~/.claude/ (CLAUDE.md, settings.json, commands, hooks, skills, statusline). bypassPermissions is merged automatically. Build context changed to repo root so Dockerfile can COPY personas/. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Users can create .devcontainer/local/ (gitignored) to layer personal customizations on top of the base persona. CLAUDE.md and statusline are overwritten; settings.json is deep-merged (dicts recursive, lists concatenated); commands/, hooks/, skills/ are additively merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension. |
vtiwari-story
approved these changes
Feb 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Opinionated devcointainer (Claude in Docker) setup and expanded instructions.
Migrates personas too.