fix: untrack a node_modules symlink carrying an absolute local path - #119
Merged
Merged
Conversation
`node_modules` was committed as a **symlink** (mode 120000) whose content is an absolute path on one contributor's machine. A fresh clone therefore gets a dangling link pointing at a directory that does not exist, and the path itself is published. `.gitignore` already had `node_modules/`. The trailing slash matches a DIRECTORY, and this is a symlink with that name, so the ignore rule never applied and `git add -A` picked it up. Both forms are now listed. How it got here, since the mechanism matters more than the file: the docs branches were built in parallel `git worktree` checkouts, and each worktree had `node_modules` symlinked to the main checkout so the VuePress build would run without a second install. `git add -A` in one of those worktrees then staged the link. The lesson is not "be careful with add -A" but that the ignore rule was shaped for the wrong object type all along — any contributor doing the same thing would have hit it. No history rewrite: the path is a local directory name, not a credential, and rewriting a public repo's history invalidates every clone and fork.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
node_modulesis tracked onmainas a symlink (mode120000) whose content is an absolute path on one contributor's machine:A fresh clone gets a dangling link pointing at a directory that does not exist, and the local path is published in a public repository.
Why the existing ignore rule did not catch it
.gitignorealready hadnode_modules/. The trailing slash matches a directory, and this is a symlink with that name — so the rule never applied andgit add -Astaged it. Both forms are now listed.How it got here
The docs branches were built in parallel
git worktreecheckouts, and each worktree hadnode_modulessymlinked back to the main checkout so the VuePress build could run without a second 297-package install. Agit add -Ain one of those worktrees staged the link.The lesson isn't "be careful with
add -A" — it's that the ignore rule was shaped for the wrong object type all along. Any contributor symlinkingnode_modulesfor any reason would have hit exactly this.Not a history rewrite
The value is a local directory path, not a credential. Rewriting a public repository's history invalidates every clone, fork and commit SHA, which is not a trade worth making here.