Skip to content
This repository was archived by the owner on Aug 2, 2026. It is now read-only.

fix(hooks): block every git clean that is not a dry run - #152

Merged
vancura merged 1 commit into
mainfrom
shell-safety
Jul 29, 2026
Merged

vancura merged 1 commit into
mainfrom
shell-safety

Conversation

@vancura

@vancura vancura commented Jul 29, 2026

Copy link
Copy Markdown
Member

Summary

Force-flag matching alone missed git -c clean.requireForce=false clean -d, which deletes untracked files without ever naming -f/--force. Now only an explicit dry run (-n/--dry-run) with no force flag is allowed through; every other invocation, including a bare git clean, is denied.

Force-flag matching alone missed `git -c clean.requireForce=false
clean -d`, which deletes untracked files without ever naming -f/--force.
Now only an explicit dry run (-n/--dry-run) with no force flag is
allowed through; every other invocation, including a bare `git clean`,
is denied.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Vaclav Vancura <commit@vancura.dev>
@vancura
vancura merged commit 5f23585 into main Jul 29, 2026
7 checks passed
@vancura
vancura deleted the shell-safety branch July 29, 2026 19:39
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant