Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

A bash-belt task landing commits node_modules when a repository has no ignore rule

Offen
#1,463 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
70/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
bash, go, node.js
Bereich
cli, testing-qa, tooling

Rechercherichtung

Start in internal/session/task_run.go around :9223, :9263, and :9341, reading the older recorded-write restriction, stageTaskWork, and beltTreeWork. Run the deterministic temporary-repository reproduction and inspect the staging tests. Done means dependency installation preserves the manifest and lockfile, excludes incidental node_modules paths, allows explicitly requested generated files, and includes the task manual and invalidates updates.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

area:session bug sev:serious

Found on santos/dev2 at 008363c98 (#1410). It reaches dev when #1410 merges.

What happened

On 2026-09-24, a /task that installed an npm dependency landed package-lock.json and 11 files under node_modules/ in a repository without .gitignore. The lockfile is an intended result; the installed dependency tree is incidental command output. The older node belt on dev stages recorded writes rather than all paths visible to Git, so this broad bash-belt landing is new to #1410.

Replication

Deterministic (no model). In a temporary Git repository with a package.json and no .gitignore, create package-lock.json and node_modules/pkg/index.js in a bash-belt task copy. Call the landing path with no recorded saving-tool writes. Today beltTreeWork includes both paths and the resulting task commit includes node_modules/pkg/index.js.

Field (real models). With OPENROUTER_API_KEY and deepseek/deepseek-v4-flash, ask /task add a dependency using npm install in a fresh repository with no ignore file. Allow several minutes and a small charge; inspect git show --stat HEAD after landing.

Where

internal/session/task_run.go:9341, beltTreeWork, collects Git-visible paths; stageTaskWork at :9263 merges them into staged work. The older belt's recorded-write restriction is described at :9223.

The fix

Distinguish declared deliverables from dependency installation output on the bash belt. Preserve lockfile changes while excluding routine dependency directories unless the brief or an explicit deliverable names them.

Acceptance

  • e2e: /task installing a dependency lands the manifest and lockfile but no node_modules/ paths in an otherwise unignored repository.
  • Unit: staging tests cover an explicitly requested generated dependency file as well as incidental output.
  • Update the task manual and invalidates.
Vorherrschende Sprache
Go
Sterne
115
Forks
14
Ø Merge
9 Std. 37 Min.
Gemergte PRs (30 T.)
755

Entwicklungsumgebung

Die Einrichtungsdateien dieses Projekts haben wir noch nicht geprüft. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus Agent-Field/CodeAF

Alle Issues in Agent-Field/CodeAF

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.