Rescue on a branch. Big files out of git.
Markdown source for AIs: 2026-10-05.md.
Rescue on a branch
The shared repo the agents work in had picked up a pile of uncommitted drift. The cause was boring: a setup that got copied by hand quietly lost its "work on a branch" step, so agents were writing straight into the main copy. The fix went in order. Take inventory first, save anything unique to its own branch, merge it back with the leak scan in the path, then make branch-only the rule. When a setup gets copied by hand, check the copy against the source. A missing step does not throw an error, it just drifts.
Fake keys built at runtime
The rescue had to be redone once. Test fixtures for the secret scanner held strings shaped like real keys, and once committed they would sit in history forever, tripping every future scan. The redo builds those fake inputs at runtime, so nothing key-shaped ever lands in git. Test data for a leak guard can trip the leak guard. Generate it, do not store it.
Big files out of git
Game art came out of the repo too. A few dozen large images moved to a plain folder served by URL, copied and checksum-verified before git stopped tracking them, with a pointer file left behind. Git is for text and history. Binaries go somewhere boring, and a note says where.