chore(registry): trim the published archive to runtime files

The registry security scan flags a node version on ANY finding, even
severity "info", so every file in node.zip is scan surface. Dev-only
trees (tests/, docs/, scripts/, .agents/, Vue widget sources) accounted
for ~44 of the 115 findings that flagged 1.2.2-1.2.4.

comfy-cli builds the archive as `git ls-files` minus `.comfyignore`
matches, so this drops 501 of 1033 tracked files while keeping every
runtime path: py/, web/, static/, templates/, locales/,
example_workflows/, data/supporters.json, refs/, standalone.py.

Dropping vue-widgets/ is deliberate: the prebuilt bundle ships in
web/comfyui/vue-widgets/, and py/vue_widget_builder.py skips its mtime
check when src/ is absent, so end-user installs no longer risk an
npm install at startup.
This commit is contained in:
Will Miao
2026-10-05 14:58:13 +08:00
parent db50632e83
commit 0e3897f09b
+50
View File
@@ -0,0 +1,50 @@
# .comfyignore — keep the Comfy Registry archive to runtime-only files.
#
# comfy-cli builds node.zip as: git-tracked files − .comfyignore matches
# + [tool.comfy].includes (we declare none). Patterns use .gitignore
# (gitwildmatch) syntax, evaluated against paths relative to the repo root.
# https://docs.comfy.org/registry/publishing
#
# Why this file exists: the registry security scan flags a version on ANY
# finding, even severity "info", so every shipped file is scan surface.
# Dev-only files (tests, docs, tooling scripts, agent notes, Vue sources)
# accounted for ~44 of the 115 findings that flagged 1.2.2–1.2.4.
# Test suites
/tests/
# Developer documentation, plans and internal notes
/docs/
/.omo/
/.specs/
/AGENTS.md
/update_logs.md
# Agent skill definitions (repo tooling, not loaded by ComfyUI)
/.agents/
# CI and repository automation
/.github/
# Repository tooling scripts — maintenance only, never imported at runtime.
# scripts/api.js + scripts/app.js are ComfyUI stubs consumed by the vitest suite.
/scripts/
# Vue widget sources and build inputs. The prebuilt bundle that actually ships
# lives in web/comfyui/vue-widgets/. Dropping the sources also stops the startup
# auto-builder from running its mtime check (and an npm install) on end-user
# machines, since py/vue_widget_builder.py skips the check when src/ is absent.
/vue-widgets/
# Root npm tooling — frontend test runner only
/package.json
/package-lock.json
/vitest.config.js
/pytest.ini
/requirements-dev.txt
# Sourcemaps are build artifacts, never loaded at runtime
web/comfyui/vue-widgets/*.js.map
# Keep this file itself out of the archive
/.comfyignore