skills: remoteHeadSha() can open a Git Credential Manager dialog on Windows (GIT_TERMINAL_PROMPT does not cover GUI helpers; slug unvalidated)
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 78/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- cli
Línea de trabajo
Empieza en packages/cli/src/utils/skillsManifest.ts, en remoteHeadSha(), y sigue el llamador de --source si es necesario. Verifica el slug antes de iniciar git, deshabilita los asistentes de credenciales y las indicaciones interactivas para esta consulta, y asegúrate de que los repositorios no válidos o inaccesibles devuelvan null sin abrir un diálogo de GUI.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
packages/cli/src/utils/skillsManifest.ts remoteHeadSha() runs
execFileAsync("git", ["ls-remote", `https://github.com/${repoSlug}.git`, "refs/heads/main"], { env: { ...process.env, GIT_TERMINAL_PROMPT: "0" } })
GIT_TERMINAL_PROMPT=0 only suppresses terminal prompts. On Windows with Git Credential Manager (the Git for Windows default), a slug for a nonexistent or private repository makes GitHub answer with an authentication challenge, and GCM opens a GUI "Connect to GitHub" window instead of failing. The function's catch never sees it because the process is blocked on the dialog until the user cancels. repoSlug is also passed through unvalidated, so any --source value shaped like a/b reaches git.
We hit the same mechanism this week through a different caller (OpenCode's plugin install, reported at https://github.com/anomalyco/opencode/issues/51943) and noticed this helper has the same latent shape while tracing it.
Suggested fix
- Validate the slug before spawning:
/^[\w.-]+\/[\w.-]+$/, else returnnull. - Spawn git so it can never prompt:
git -c credential.helper= ls-remote ...plusGCM_INTERACTIVE: "never"andGIT_ASKPASS: ""in the env. An anonymous read of a public repo never needs a credential helper, so disabling it for this call loses nothing.
Low priority; reported for completeness while the details were fresh.
- Lenguaje dominante
- TypeScript
- Estrellas
- 54.1k
- Forks
- 4.9k
- Merge medio
- 7 h 18 min
- PR fusionados (30 d)
- 784
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de heygen-com/hyperframes
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
heygen-com/hyperframes#5027 ·
Los mantenedores suelen responder en 1 día
-
fix(producer): propagate useGpu to HDR layered streaming encoderPosiblemente ocupada @Monster-GM la tomó hace 1 día. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 87/100
heygen-com/hyperframes#5002 ·
Los mantenedores suelen responder en 1 día
-
Studio catalog prompt editor has no accessible namePosiblemente ocupada @lorenzozanee la tomó hace 12 días. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
heygen-com/hyperframes#4384 ·
Los mantenedores suelen responder en 1 día
-
lint: validate composition variables declared on supported root elementsQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
heygen-com/hyperframes#4383 ·
Los mantenedores suelen responder en 1 día
-
lint: report AVIF/M4A media-kind mismatches consistently with JPEG/MP3Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 91/100
heygen-com/hyperframes#4382 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de heygen-com/hyperframes
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
Los mantenedores suelen responder en 1 día
-
Signals (Failure Detector): a tool call and its own execution are reported as a repeated callAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
platformatic/mcp#208 ·
Los mantenedores suelen responder en 1 día
-
🐛 bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
margelo/react-native-vision-camera#4211 ·
Los mantenedores suelen responder en 4 días