Skip to content

Upgrade Plan docs - #3

Open
anveo wants to merge 1 commit into
mainfrom
audit-2026-08
Open

Upgrade Plan docs#3
anveo wants to merge 1 commit into
mainfrom
audit-2026-08

Conversation

@anveo

@anveo anveo commented Jul 30, 2026

Copy link
Copy Markdown
Owner

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new long-form audit document capturing security findings, broken configuration behavior, bootstrap issues, and modernization recommendations for this dotfiles repo.

Changes:

  • Add a comprehensive dotfiles audit report dated 2026-07-29.
  • Document prioritized security fixes, current breakages, and a proposed upgrade/modernization path.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.


- **Your global gitignore has never applied.** `.gitconfig:62` `excludesfile = $HOME/.gitignore` — git doesn't expand `$HOME` in config values (only leading `~/`). **[verified]** two independent ways (`git config --path` returns the literal string; `git check-ignore` misses `Thumbs.db`). The whole `.gitignore.global → ~/.gitignore` symlink machinery is inert. One-character fix: `~/.gitignore`.
- **Same class:** `~/.gitattributes` is symlinked by install.sh but git never reads that path — `core.attributesfile` is unset **[verified]**. The symlink does nothing.
- **`diff.external = difft` hijacks every diff** (`.gitconfig:114`): `git diff` output is no longer a valid patch (breaks `| git apply`, `--stat` accuracy) and it fires for `git log -p`, so your `l`/`ll`/`dl`/`news`/`pik` aliases all emit non-patch output. Meanwhile git-delta is installed and completely unused. Recommended shape: difftastic stays as difftool (`git dft`), delta becomes the pager (see §6).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants