github / github/copilot.vim

Automatically disable copilot in dotenv files

未關閉
#135 0 則留言 9 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Vim Script
星號
11.7k
分支
810
PR 合併指標
30 天內沒有已合併 PR

描述

It seems like a big security issue to have Copilot running by default within dotenv files (i.e. `.env`) that contain extremely sensitive information (API keys, access tokens, passwords, etc).

Can this be disabled by default?

I've circumvented this locally with this code in my vimrc:

```vimscript
augroup dotenv_detect
autocmd!
autocmd BufRead,BufNewFile *.env,*.env.* set filetype=dotenv
augroup END

let g:copilot_filetypes = {
\ '*': v:true,
\ 'dotenv': v:false
\ }
```

But this feels like a pretty general best practice that should be opt-out, not opt-in.

貢獻指南

開啟貢獻指南

研究方向

以 vimrc workaround 作為行為參考:對於 .env 和 .env.* 等 dotenv 檔案,Copilot 預設應處於停用狀態。先追蹤 filetypes 的偵測方式以及 g:copilot_filetypes 的套用方式,然後確認一般的 filetypes 仍保持啟用,而 dotenv 檔案預設處於停用狀態。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
vim
領域
devtools, security
Issue 類型
功能
難度
2/5
預估耗時
1-3 小時
活躍度
停滯
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。