FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

fix(cli): remove .git folder when creating project from git template by OlegHQ · Pull Request #13239 · serverless/serverless · GitHub

Repository navigation

fix(cli): remove .git folder when creating project from git template - #13239

Open
OlegHQ wants to merge 2 commits into
serverless:mainfrom
OlegHQ:fix/remove-git-folder-from-template
Open

OlegHQ wants to merge 2 commits into
serverless:mainfrom
OlegHQ:fix/remove-git-folder-from-template

Conversation

OlegHQ commented Jan 9, 2026

Copy link
Copy Markdown

When creating a project from a git template URL, the .git folder is copied to the new project, causing git to track the template repository instead of being ready for a new repository.

This change removes the .git folder after cloning the template, so the new project starts fresh without any git history.

Verification

Environment: Darwin (arm64)
Runtime: Node.js v24.11.1

Test Steps

  1. npm install
  2. npm run test:unit -w @serverlessinc/sf-core -- --testPathPattern=download.test

Results

Test Suites: 24 passed, 24 total
Tests: 368 passed, 368 total

All unit tests pass, including new tests that verify the .git folder removal behavior.

Closes: #11978

OlegHQ added 2 commits January 9, 2026 22:40
When using `--template-url` with a plain Git URL (e.g., git@bitbucket.org:...
or https://example.com/repo.git), the template is cloned via git clone.
Previously, the .git folder was left in the new project, causing it to
point to the template repository instead of being a fresh project.

This change:
- Adds git clone support for plain Git URLs (both HTTPS and SSH)
- Removes the .git folder after cloning to disassociate from template repo
- Handles SSH URLs (git@...) that cannot be parsed as standard URLs
- Adds test coverage for the new git clone and .git removal behavior

Fixes serverless#11978
- Replace child_process.exec() with spawn() using array arguments
- Add input validation to reject URLs with shell metacharacters
- Remove console.error in favor of silent error handling
- Add test for command injection prevention

github-actions Bot commented Jan 9, 2026 •
edited
Loading

Copy link
Copy Markdown

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Mmarzex commented Jan 9, 2026 •
edited
Loading

Copy link
Copy Markdown
Contributor

✅ Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

OlegHQ commented Jan 9, 2026

Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

creating a project from private git repo copies the .git folder

2 participants


Back | FazBrowse Home | New Git URL