feat(security): gate executable shared/ dotfiles + empty-profile warning - #158
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 2 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (7)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
019083b to
ce4cfd5
Compare
Summary
shared/(.zshrc,.bashrc, etc.) behind--include-dotfilesCLI flag, mirroring--include-hooksbehavior. By default these files are skipped with a warning.Changes
DANGEROUS_SHARED_DOTFILESdenylist insrc/plan.ts(11 shell startup files)isExecutable()to gate shared/ dotfiles alongsideclaude/settings.jsonincludeDotfilesparameter throughout install/update pipeline (plan → apply → backup)printPlan()to display warnings for both hooks and dangerous dotfiles--include-dotfilesflag toinstallandupdatecommands in CLIinstall()command (exits 1, shows warning)Test Plan
npm test— all 167 tests pass including newdotfiles-and-empty.test.tsnpm run typecheck— passesnpm run format:check— passessharekit install <profile-with-.zshrc>shows warning, skips file unless--include-dotfilesusedCloses #145
Closes #151