Undocumented `logs/security/.security-key` file created in every working directory on startup
- Ngôn ngữ chính
- Shell
- Star
- 11.2k
- Fork
- 1.9k
- Merge trung bình
- 14 giờ 16 phút
- Pull request đã merge (30 ngày)
- 6
Mô tả
# Description
Copilot CLI creates a `logs/security/.security-key` file in the current working directory as soon as a session starts. This happens in every directory, including a brand-new empty one, so it appears to be unconditional CLI startup behavior rather than something tied to a specific repo or project config.
I can't find this documented anywhere - not in the CLI config-directory reference, the command reference, or recent changelogs (checked back through v1.0.76). Filing this to understand what the file is for and whether it's expected to live in the project directory rather than `~/.copilot/`.
# Steps to reproduce
```bash
mkdir /tmp/test-copilot && cd /tmp/test-copilot && copilot
# exit the session
ls -la logs/security/
```
# Observed
```bash
harshit@Harshits-MacBook-Pro /tmp/test-copilot » ls -la logs/security
total 8
drwxr-xr-x@ 3 harshit wheel 96 Jul 31 10:52 .
drwxr-xr-x@ 3 harshit wheel 96 Jul 31 10:52 ..
-rw-------@ 1 harshit wheel 32 Jul 31 10:52 .security-key
```
The file contains 32 bytes of what appears to be binary/random data (confirmed via xxd), not human-readable text.
# Questions
1. What is this file used for (e.g., local encryption of session state, sandbox integrity verification, telemetry)?
2. Is it intentional that it's written under `/logs/security/` rather than under `~/.copilot/`? This means every project directory a user runs copilot in accumulates this file, which could easily get committed to version control if not gitignored.
3. Should this path be added to a default `.gitignore` suggestion, or documented in the config-directory reference alongside the other `~/.copilot/` contents?
# Environment
- Copilot CLI version: GitHub Copilot CLI 1.0.77
- OS: macOS 26.4 (25E246)
- Install method: I don't remember, I have been using copilot for a while now. The only change that happened is I recently updated the version.
Hướng dẫn đóng góp
Hướng nghiên cứu
Chạy quy trình tái hiện mkdir, cd, copilot và ls được cung cấp trong một thư mục trống, sau đó lần theo đường dẫn khởi động CLI tạo ra logs/security/.security-key. Đọc tài liệu tham chiếu về thư mục cấu hình CLI, tài liệu tham chiếu lệnh và các changelog được đề cập trong báo cáo. Được xem là hoàn tất khi mục đích và vị trí dự kiến của tệp đã được xác định, đồng thời hành vi đã được sửa hoặc ghi lại cùng với mọi hướng dẫn về gitignore.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- shell
- Lĩnh vực
- cli, documentation
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 45/100