skills: remoteHeadSha() can open a Git Credential Manager dialog on Windows (GIT_TERMINAL_PROMPT does not cover GUI helpers; slug unvalidated)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- cli
Hướng nghiên cứu
Bắt đầu trong packages/cli/src/utils/skillsManifest.ts tại remoteHeadSha() và lần theo caller của --source nếu cần. Xác minh slug trước khi khởi chạy git, vô hiệu hóa credential helpers và các prompt tương tác cho lần tra cứu này, đồng thời đảm bảo các repository không hợp lệ hoặc không thể truy cập trả về null mà không mở hộp thoại GUI.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
packages/cli/src/utils/skillsManifest.ts remoteHeadSha() runs
execFileAsync("git", ["ls-remote", `https://github.com/${repoSlug}.git`, "refs/heads/main"], { env: { ...process.env, GIT_TERMINAL_PROMPT: "0" } })
GIT_TERMINAL_PROMPT=0 only suppresses terminal prompts. On Windows with Git Credential Manager (the Git for Windows default), a slug for a nonexistent or private repository makes GitHub answer with an authentication challenge, and GCM opens a GUI "Connect to GitHub" window instead of failing. The function's catch never sees it because the process is blocked on the dialog until the user cancels. repoSlug is also passed through unvalidated, so any --source value shaped like a/b reaches git.
We hit the same mechanism this week through a different caller (OpenCode's plugin install, reported at https://github.com/anomalyco/opencode/issues/51943) and noticed this helper has the same latent shape while tracing it.
Suggested fix
- Validate the slug before spawning:
/^[\w.-]+\/[\w.-]+$/, else returnnull. - Spawn git so it can never prompt:
git -c credential.helper= ls-remote ...plusGCM_INTERACTIVE: "never"andGIT_ASKPASS: ""in the env. An anonymous read of a public repo never needs a credential helper, so disabling it for this call loses nothing.
Low priority; reported for completeness while the details were fresh.
- Ngôn ngữ chính
- TypeScript
- Star
- 54.1k
- Fork
- 4.9k
- Merge trung bình
- 7 giờ 29 phút
- Pull request đã merge (30 ngày)
- 778
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của heygen-com/hyperframes
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
heygen-com/hyperframes#5027 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
fix(producer): propagate useGpu to HDR layered streaming encoderCó thể đã có người làm @Monster-GM đã nhận 1 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 87/100
heygen-com/hyperframes#5002 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Studio catalog prompt editor has no accessible nameCó thể đã có người làm @lorenzozanee đã nhận 12 ngày trước. Đang mởbug difficulty/easy triage/ready
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
heygen-com/hyperframes#4384 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
lint: validate composition variables declared on supported root elementsCó thể làm lại được Pull request cho issue này đã bị đóng mà không được merge. Đang mởbug difficulty/easy triage/ready
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
heygen-com/hyperframes#4383 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
lint: report AVIF/M4A media-kind mismatches consistently with JPEG/MP3Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởbug difficulty/easy triage/ready
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 91/100
heygen-com/hyperframes#4382 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của heygen-com/hyperframes
Issue tương tự
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated oneĐang mởdata-lake
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement good first issue priority: low size: XS
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Empty label or headline exports the editor hint ("LABEL" / "Headline goes here") into the PNGĐang mở
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 88/100
-
Spray wall wizard: Done button on the hold review step sits under the navigation header (iOS)Đang mởbug ios mobile priority:P1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
streamplace/streamplace#1351 ·
Maintainer thường phản hồi trong vòng 2 ngày