github / github/copilot-cli

DESTRUCTIVE (forced) git branch deletion is MISCLASSIFIED and requires NO PERMISSION

Offen
#4,156 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:permissions area:tools
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

### Describe the bug

Per `/diagnose`:

---

Found it. The root cause is clear from the event log:

- **`git push --delete`** at 20:42:24 → generated a `permission.request` event → you were prompted ✅
- **`git branch -D`** at 20:43:03 → **no `permission.request` event at all** → ran silently ❌

The CLI classifies commands by identifier to determine if they're read-only. In the `git push` permission request, `git push` is correctly tagged `"readOnly": false`. But earlier in the session, `git branch -r` was tagged `"readOnly": true` — and the classifier appears to treat **all `git branch` invocations as read-only**, regardless of flags like `-D`.

In short: **this is a classifier bug in the CLI**. It doesn't recognize that `git branch -D` is destructive, so it skips the permission prompt entirely. `git push --delete` was correctly flagged; `git branch -D` was not.

This is worth reporting via `/feedback` — the `git branch` command classifier needs to recognize `-D` / `-d` / `--delete` as write operations.

### Affected version

GitHub Copilot CLI 1.0.71.

### Steps to reproduce the behavior

- Ask Copilot to delete one or more remote branches to provoke it to call `git push --delete ...`.
- Observe that the command requires user acknowledgement.
- Ask Copilot to delete one or more local branches to provoke it to call `git branch -D ...`.
- Observe that the command runs with no permission prompt.

### Expected behavior

A destructive operation such as DELETING A BRANCH should require confirmation by default.

### Additional context

_No response_

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne beim CLI-Befehlsklassifizierer und untersuche, wie git branch-Identifikatoren den Ereignissen readOnly und permission.request zugeordnet werden. Reproduziere dies mit git branch -D, -d und --delete und überprüfe anschließend, dass destruktive Varianten eine Bestätigung erfordern, während git branch -r schreibgeschützt bleibt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git
Bereich
cli, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.