Skip to content

fix(core): treat git commands that destroy the way back as destructive - #104

Open
moise10r wants to merge 2 commits into
mainfrom
fix/32-git-reflog-expire-is-a-read-and-refspec-force
Open

moise10r wants to merge 2 commits into
mainfrom
fix/32-git-reflog-expire-is-a-read-and-refspec-force

Conversation

@moise10r

@moise10r moise10r commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What this changes

git reflog expire was classed as a read, and a +refspec push slipped past the force push rule. Each command below is now a destructive action of its own, and the baseline git deny rule lists all of them. A +refspec push resolves exactly like push --force. A :name push is git.push-delete, while a bare : stays an ordinary push.

Classes that moved, to destructive:

  • reflog expire and reflog delete
  • stash clear and stash drop
  • push --delete and push -d
  • clean --force
  • branch --delete --force
  • filter-branch and filter-repo
  • gc --prune=now

How it was verified

packages/core/test/verb-table.test.ts pins every command in the issue. It also checks that both +refspec forms match push --force and that a bare : stays a plain push. domains.test.ts still asserts the baseline rule covers every destructive git verb.

Fixes #32

Checklist

  • pnpm format && pnpm typecheck && pnpm test && pnpm deadcode all pass
  • Behaviour change ships with a test
  • No any, no magic values, no console.* outside cli-output.ts
  • If this touches the decision path: still deterministic — no LLM, network, or randomness
  • If this changes a verb table: the classes that moved are named above
  • If this changes a command, flag or file it writes: docs/ says so (not applicable)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

verbs: git reflog expire is a read, and '+refspec' force pushes bypass the git.push-force rule

1 participant