Skip to content

fix(discovery): never walk dependency folders, at any depth - #126

Merged
Shinrai merged 2 commits into
nextfrom
fix/ignore-dependency-folders
Oct 4, 2026
Merged

Shinrai merged 2 commits into
nextfrom
fix/ignore-dependency-folders

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

No new features

🐛 Bug Fixes

📦 Dependencies

No dependency updates

🔧 Other Changes

No other changes

👥 Contributors

@cldmv-bot cldmv-bot Bot added ! fix → next v4 flow: fix contributor PR targeting the next integration branch area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure type: documentation Relates to docs, README updates, guides, or inline code comments labels Oct 4, 2026
Discovery skipped only .git by name, so a project without a .gitignore (or
a sub-package with its own node_modules, or a tracked dependency folder,
or gitignore: false) had headers stamped into installed packages.

Dependency folders are now never walked, at any depth and whatever the
ignore files say: node_modules, bower_components, jspm_packages,
.pnpm-store and .yarn, plus a vendor folder that holds Composer's
autoload.php or Go's modules.txt. Other folders named vendor are still
processed, since the name is also used for code a project maintains
itself (front-end vendor/ scripts, Laravel's resources/views/vendor).
A path inside a dependency folder that is named explicitly, through
includeFolders / --include-folder or input / --input, is still processed.

Build output (dist, build, coverage, ...) keeps being processed unless an
ignore file or excludeFolders says otherwise. Tests from #71 that expected
node_modules to be walked are updated to the new rule.

Fixes #123
@Shinrai
Shinrai force-pushed the fix/ignore-dependency-folders branch from 523cd89 to adb3d7c Compare October 4, 2026 00:41
Shinrai added a commit that referenced this pull request Oct 4, 2026
The non-JS file, repeatable --input and dependency-folder fixes land in
the same release as #117. Describe each fix, the reported skips, and the
behaviour changes an existing setup could notice.
Shinrai
Shinrai previously approved these changes Oct 4, 2026
@cldmv-bot
cldmv-bot Bot dismissed Shinrai’s stale review October 4, 2026 01:21

The merge-base changed after approval.

@Shinrai
Shinrai enabled auto-merge October 4, 2026 01:22
@Shinrai
Shinrai merged commit e31ef42 into next Oct 4, 2026
24 checks passed
@cldmv-bot
cldmv-bot Bot deleted the fix/ignore-dependency-folders branch October 4, 2026 01:23
Shinrai added a commit that referenced this pull request Oct 4, 2026
…#121)

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
- fix(discovery): never walk dependency folders, at any depth (#121)
(adb3d7c)
- fix(cli): process every --input value instead of only the last (#121)
(be9b89b)
- fix: never write a comment into files that cannot carry one;
force-only Markdown headers (#121) (082977f)

### 📦 Dependencies
_No dependency updates_

### 🔧 Other Changes
- docs: cover #124, #125 and #126 in the v2.1.4 notes and What's New
(#121) (13c8859)
- docs: add the v2.1.4 changelog and restructure the README (#121)
(0358f40)
- docs(changelog): backfill changelogs for v1.0.0–v1.3.12, v2.1.1 and
v2.1.2 (#121) (caa7c1e)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! fix → next v4 flow: fix contributor PR targeting the next integration branch type: documentation Relates to docs, README updates, guides, or inline code comments

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant