Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

create: overwrite follows target symlinks and deletes linked contents

Open
#2,419 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
rust
Domain
cli

Research direction

Review the vp create overwrite flow and the draft fix in #2418, then reproduce the symlink case from this issue on macOS or another local filesystem. Done means confirming that “Remove existing files and continue” does not delete contents outside the symlink entry and that the prompt or behavior makes any resolved target explicit.

Written by the indexing model from the issue text.

Description

Summary

When vp create targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.

The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.

Reproduction

  1. Create a directory containing a sentinel file:

    mkdir linked-directory
    printf 'keep\n' > linked-directory/keep.txt
    
  2. Create a target directory symlink:

    ln -s "$PWD/linked-directory" new-project
    
  3. Start any vp create flow with new-project as its target directory.

  4. When prompted, select “Remove existing files and continue”.

  5. Check the linked directory:

    test -e linked-directory/keep.txt
    

Actual behavior

linked-directory/keep.txt is deleted. Other entries in the linked directory are also removed recursively, except for the existing .git preservation behavior.

Expected behavior

The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.

It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.

Impact

This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.

The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.

Environment

  • Reproduced on macOS arm64
  • Node.js v25.9.0
  • Vite+ revision: 295c8d6069605a249ed39e8c5e4d4d3d79e4be3e

A draft fix is available in #2418.

Dominant language
Rust
Stars
6k
Forks
271
Avg merge
19h 51m
Merged PRs (30d)
140

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from voidzero-dev/vite-plus

All issues in voidzero-dev/vite-plus

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.