Exclude Git metadata from local extension installs - #1329
Conversation
Apply a shared SDK copy policy to install plans and runtime copies so root and nested .git directories, worktree files, and symlinks are omitted and counted. Verify project and global activation with a real Git checkout regression and a disposable CLI acceptance run. Close the tracked defect with exact coverage and package smoke evidence, regenerate the changelog, and record current release, quality-gate, and historical tracker observations.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (18)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughLocal extension installs now exclude Git metadata from copied sources. The change updates copy planning and runtime filtering, adds checkout-based regression coverage, and records the policy and related validation results. ChangesLocal package copy behavior
PM validation and run updates
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix · Severity of issue fixed: Medium Possibly related PRs
Merge Risk: ⚪ Minimal · up to The reliability record needs no correction, and the supplied evidence identifies no remaining issue that should block this change. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change reduces Git-metadata exposure in copied extensions, and no new public install path or weakened containment control was identified. Differently named links to Git metadata and abrupt interruption remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Out of Scope Changes checkExplanation The implementation, tests, documentation, changelog, and
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideLocal extension directory installs now use a shared filtering policy that excludes Git metadata—including nested Sequence diagram for Git metadata exclusion during extension installsequenceDiagram
participant CLI
participant Planner
participant Runtime
participant Filesystem
CLI->>Planner: scanExtensionCopyDirectory
loop each directory entry
Planner->>Planner: includesExtensionCopyPath
alt path includes .git
Planner->>Planner: increment excluded_entries
else path is allowed
Planner->>Planner: include entry in install plan
end
end
CLI->>Runtime: copyExtensionDirectoryWithoutSelfNesting
Runtime->>Filesystem: copyDirectory
Filesystem->>Runtime: evaluate filter
Runtime->>Runtime: includesExtensionCopyPath
alt path includes .git
Runtime-->>Filesystem: skip entry
else path is allowed
Runtime-->>Filesystem: copy entry
end
File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Summary
.gitdirectories, worktree files, and symlinks at every depth from extension directory installs. The SDK install plan and runtime copy now use the same policy, and the plan counts excluded entries.CHANGELOG.mdwith the currentpm-changelogpackage and carry PM closeout and live audit evidence in the reviewed branch.PM lineage
Closes #1324.
Verification
.gitmetadata.Summary by Sourcery
Exclude Git metadata from local extension installs while keeping planning, runtime copying, documentation, and regression coverage consistent.
Bug Fixes:
Enhancements:
Documentation:
Tests:
Chores:
Summary by cubic
Fixes local extension directory installs copying the source checkout's Git metadata (
.gitconfig, refs, object history) into the managed extension..gitdirectories, worktree files, and symlinks at every depth, with excluded entries counted in the plan.pm-k7nxaz(Closes Local package install copies .git repository history into managed extension #1324).Written for commit d616195. Summary will update on new commits.