skills: remoteHeadSha() can open a Git Credential Manager dialog on Windows (GIT_TERMINAL_PROMPT does not cover GUI helpers; slug unvalidated)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- typescript
- 领域
- cli
调研方向
从 packages/cli/src/utils/skillsManifest.ts 中的 remoteHeadSha() 开始,并在需要时跟踪 --source 的调用方。在启动 git 之前验证 slug,为此次查找禁用凭据助手和交互式提示,并确保无效或无法访问的仓库返回 null,而不会打开 GUI 对话框。
由索引模型根据 Issue 内容生成。
描述
Summary
packages/cli/src/utils/skillsManifest.ts remoteHeadSha() runs
execFileAsync("git", ["ls-remote", `https://github.com/${repoSlug}.git`, "refs/heads/main"], { env: { ...process.env, GIT_TERMINAL_PROMPT: "0" } })
GIT_TERMINAL_PROMPT=0 only suppresses terminal prompts. On Windows with Git Credential Manager (the Git for Windows default), a slug for a nonexistent or private repository makes GitHub answer with an authentication challenge, and GCM opens a GUI "Connect to GitHub" window instead of failing. The function's catch never sees it because the process is blocked on the dialog until the user cancels. repoSlug is also passed through unvalidated, so any --source value shaped like a/b reaches git.
We hit the same mechanism this week through a different caller (OpenCode's plugin install, reported at https://github.com/anomalyco/opencode/issues/51943) and noticed this helper has the same latent shape while tracing it.
Suggested fix
- Validate the slug before spawning:
/^[\w.-]+\/[\w.-]+$/, else returnnull. - Spawn git so it can never prompt:
git -c credential.helper= ls-remote ...plusGCM_INTERACTIVE: "never"andGIT_ASKPASS: ""in the env. An anonymous read of a public repo never needs a credential helper, so disabling it for this call loses nothing.
Low priority; reported for completeness while the details were fresh.
- 主要语言
- TypeScript
- 星标
- 54.1k
- 派生
- 4.9k
- 平均合并
- 7 小时 18 分钟
- 30 天内合并 PR
- 784
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
heygen-com/hyperframes 的其他 Issue
-
Docs: clarify that "Enable auto-update" is only available in the Claude Code terminal (CLI) /plugin UI可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 85/100
heygen-com/hyperframes#5027 ·
维护者通常 1 天内回复
-
fix(producer): propagate useGpu to HDR layered streaming encoder可能已有人在做 @Monster-GM 于 2 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 87/100
heygen-com/hyperframes#5002 ·
维护者通常 1 天内回复
-
Studio catalog prompt editor has no accessible name可能已有人在做 @lorenzozanee 于 12 天前认领。 未关闭bug difficulty/easy triage/ready
难度 2/5 1-3 小时 新手友好度 78/100
heygen-com/hyperframes#4384 ·
维护者通常 1 天内回复
-
lint: validate composition variables declared on supported root elements可能重新可做 关联的 PR 已关闭且未合并。 未关闭bug difficulty/easy triage/ready
难度 2/5 1-3 小时 新手友好度 88/100
heygen-com/hyperframes#4383 ·
维护者通常 1 天内回复
-
lint: report AVIF/M4A media-kind mismatches consistently with JPEG/MP3可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭bug difficulty/easy triage/ready
难度 2/5 1-3 小时 新手友好度 91/100
heygen-com/hyperframes#4382 · 1 条评论 ·
维护者通常 1 天内回复
查看 heygen-com/hyperframes 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 85/100
wardian-app/Wardian#1603 ·
维护者通常 1 天内回复
-
Sign the pledge未关闭
难度 1/5 1 小时以内 新手友好度 85/100
input-output-hk/devx-updates#168 ·
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
agent-ready area: config area: skills type: chore upstream: brain-kit
难度 1/5 1 小时以内 新手友好度 95/100
-
dev experience frontend good first issue
难度 2/5 1-3 小时 新手友好度 78/100
cuttle-cards/cuttle#1403 ·
维护者通常 1 天内回复