Skip to content

Default run rewrites files in node_modules when there is no .gitignore; dependency folders must always be ignored, at any depth #123

Description

@Shinrai

Problem

In a project with no .gitignore, a default repo-wide run processes dependency code. Reproduced on @cldmv/fix-headers@2.1.3, in a fresh git project with one source file plus node_modules from npm i -D @cldmv/fix-headers:

npx fix-headers --dry-run --verbose
# fix-headers complete: scanned=7, updated=7, dryRun=true
# updated: a.mjs
# updated: node_modules/@cldmv/fix-headers/bin/fix-headers.mjs
# updated: node_modules/@cldmv/fix-headers/dist/index.cjs
# updated: node_modules/@cldmv/fix-headers/dist/index.mjs
# updated: node_modules/ignore/index.d.ts
# updated: node_modules/ignore/index.js
# updated: node_modules/ignore/legacy.js

Without --dry-run, that stamps headers into installed packages. The always-ignored folder set in the discovery walker is just .git (new Set([".git"]) in the built dist/index.mjs). Everything else depends on the project's .gitignore, or on the root-only skip for dist/build/coverage added in v1.3.0. So a project without a .gitignore, a subfolder package with its own node_modules, or a monorepo package nested below the root is all exposed.

Expected

Common dependency and library folders are ignored by default, at any depth, whatever .gitignore says: node_modules, bower_components, jspm_packages, vendor (where it's a dependency folder), .pnpm-store, .yarn (cache/unplugged), plus .git. Users can still opt a folder back in with an explicit include, such as --include-folder, or a config override. A folder named directly via --input or --include-folder should still be processed, since that's an explicit request.

Keep the existing root-only behaviour for build output (dist, build, coverage), which v1.3.0 deliberately limited to the root. This issue is about dependency folders, which are never the project's own source.

Tests

  • A project with no .gitignore, nested node_modules at the root and inside a sub-package: a default run touches neither.
  • node_modules at depth 3 or more is skipped.
  • An explicit --include-folder node_modules/x is still honoured.
  • Document the default-ignored list in the README options section.

Related: #119, #120, #122 (same release).

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: coreTouches core library / runtime source codepriority: highNeeds attention soon — not blocking, but don't let it sitstatus: implementedBuilt and deployed, but not yet fully tested/verifiedtype: bugSomething is broken or not behaving as expected

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions