Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

A bash-belt task landing commits node_modules when a repository has no ignore rule

未关闭
#1,463 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
70/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
bash, go, node.js

调研方向

Start in internal/session/task_run.go around :9223, :9263, and :9341, reading the older recorded-write restriction, stageTaskWork, and beltTreeWork. Run the deterministic temporary-repository reproduction and inspect the staging tests. Done means dependency installation preserves the manifest and lockfile, excludes incidental node_modules paths, allows explicitly requested generated files, and includes the task manual and invalidates updates.

由索引模型根据 Issue 内容生成。

描述

area:session bug sev:serious

Found on santos/dev2 at 008363c98 (#1410). It reaches dev when #1410 merges.

What happened

On 2026-09-24, a /task that installed an npm dependency landed package-lock.json and 11 files under node_modules/ in a repository without .gitignore. The lockfile is an intended result; the installed dependency tree is incidental command output. The older node belt on dev stages recorded writes rather than all paths visible to Git, so this broad bash-belt landing is new to #1410.

Replication

Deterministic (no model). In a temporary Git repository with a package.json and no .gitignore, create package-lock.json and node_modules/pkg/index.js in a bash-belt task copy. Call the landing path with no recorded saving-tool writes. Today beltTreeWork includes both paths and the resulting task commit includes node_modules/pkg/index.js.

Field (real models). With OPENROUTER_API_KEY and deepseek/deepseek-v4-flash, ask /task add a dependency using npm install in a fresh repository with no ignore file. Allow several minutes and a small charge; inspect git show --stat HEAD after landing.

Where

internal/session/task_run.go:9341, beltTreeWork, collects Git-visible paths; stageTaskWork at :9263 merges them into staged work. The older belt's recorded-write restriction is described at :9223.

The fix

Distinguish declared deliverables from dependency installation output on the bash belt. Preserve lockfile changes while excluding routine dependency directories unless the brief or an explicit deliverable names them.

Acceptance

  • e2e: /task installing a dependency lands the manifest and lockfile but no node_modules/ paths in an otherwise unignored repository.
  • Unit: staging tests cover an explicitly requested generated dependency file as well as incidental output.
  • Update the task manual and invalidates.
主要语言
Go
星标
115
派生
14
平均合并
9 小时 44 分钟
30 天内合并 PR
766

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Agent-Field/CodeAF 的其他 Issue

查看 Agent-Field/CodeAF 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。