Problem
In a project with no .gitignore, a default repo-wide run processes dependency code. Reproduced on @cldmv/fix-headers@2.1.3, in a fresh git project with one source file plus node_modules from npm i -D @cldmv/fix-headers:
npx fix-headers --dry-run --verbose
# fix-headers complete: scanned=7, updated=7, dryRun=true
# updated: a.mjs
# updated: node_modules/@cldmv/fix-headers/bin/fix-headers.mjs
# updated: node_modules/@cldmv/fix-headers/dist/index.cjs
# updated: node_modules/@cldmv/fix-headers/dist/index.mjs
# updated: node_modules/ignore/index.d.ts
# updated: node_modules/ignore/index.js
# updated: node_modules/ignore/legacy.js
Without --dry-run, that stamps headers into installed packages. The always-ignored folder set in the discovery walker is just .git (new Set([".git"]) in the built dist/index.mjs). Everything else depends on the project's .gitignore, or on the root-only skip for dist/build/coverage added in v1.3.0. So a project without a .gitignore, a subfolder package with its own node_modules, or a monorepo package nested below the root is all exposed.
Expected
Common dependency and library folders are ignored by default, at any depth, whatever .gitignore says: node_modules, bower_components, jspm_packages, vendor (where it's a dependency folder), .pnpm-store, .yarn (cache/unplugged), plus .git. Users can still opt a folder back in with an explicit include, such as --include-folder, or a config override. A folder named directly via --input or --include-folder should still be processed, since that's an explicit request.
Keep the existing root-only behaviour for build output (dist, build, coverage), which v1.3.0 deliberately limited to the root. This issue is about dependency folders, which are never the project's own source.
Tests
- A project with no
.gitignore, nested node_modules at the root and inside a sub-package: a default run touches neither.
node_modules at depth 3 or more is skipped.
- An explicit
--include-folder node_modules/x is still honoured.
- Document the default-ignored list in the README options section.
Related: #119, #120, #122 (same release).
Problem
In a project with no
.gitignore, a default repo-wide run processes dependency code. Reproduced on@cldmv/fix-headers@2.1.3, in a fresh git project with one source file plusnode_modulesfromnpm i -D @cldmv/fix-headers:Without
--dry-run, that stamps headers into installed packages. The always-ignored folder set in the discovery walker is just.git(new Set([".git"])in the builtdist/index.mjs). Everything else depends on the project's.gitignore, or on the root-only skip fordist/build/coverageadded in v1.3.0. So a project without a.gitignore, a subfolder package with its ownnode_modules, or a monorepo package nested below the root is all exposed.Expected
Common dependency and library folders are ignored by default, at any depth, whatever
.gitignoresays:node_modules,bower_components,jspm_packages,vendor(where it's a dependency folder),.pnpm-store,.yarn(cache/unplugged), plus.git. Users can still opt a folder back in with an explicit include, such as--include-folder, or a config override. A folder named directly via--inputor--include-foldershould still be processed, since that's an explicit request.Keep the existing root-only behaviour for build output (
dist,build,coverage), which v1.3.0 deliberately limited to the root. This issue is about dependency folders, which are never the project's own source.Tests
.gitignore, nestednode_modulesat the root and inside a sub-package: a default run touches neither.node_modulesat depth 3 or more is skipped.--include-folder node_modules/xis still honoured.Related: #119, #120, #122 (same release).