diff --git a/config/pi/extensions/block-dangerous-git.ts b/config/pi/extensions/block-dangerous-git.ts index 5463d90..8f11ff7 100644 --- a/config/pi/extensions/block-dangerous-git.ts +++ b/config/pi/extensions/block-dangerous-git.ts @@ -2,14 +2,13 @@ import { isToolCallEventType } from "@earendil-works/pi-coding-agent"; import type { ExtensionAPI } from "@earendil-works/pi-coding-agent"; const gitPushPattern = /(^|[\s&|;(])git\s+push/; -const forcePushPattern = /(^|\s)(-f|--force|--force-with-lease)([\s=]|$)/; +const forcePushPattern = /(^|\s)(-f|--force)([\s=]|$)/; const protectedBranchPushPattern = /(^|[\s&|;(])git\s+push([^&|;]*[\s:/])(refs\/heads\/)?(master|main)([\s&|;:]|$)/; const dangerousPatterns = [ /git reset --hard/, /git clean -fd/, /git clean -f/, - /git branch -D/, /git checkout \./, /git restore \./, /reset --hard/, diff --git a/modules/claude/block-dangerous-git.sh b/modules/claude/block-dangerous-git.sh index 02c14cc..2a4df8c 100755 --- a/modules/claude/block-dangerous-git.sh +++ b/modules/claude/block-dangerous-git.sh @@ -11,7 +11,7 @@ block() { # git push: allow non-force pushes to feature branches, but block force pushes # and pushes that name a protected branch in the push command itself. if echo "$COMMAND" | grep -qE '(^|[[:space:]&|;(])git[[:space:]]+push'; then - if echo "$COMMAND" | grep -qE '(^|[[:space:]])(-f|--force|--force-with-lease)([[:space:]=]|$)'; then + if echo "$COMMAND" | grep -qE '(^|[[:space:]])(-f|--force)([[:space:]=]|$)'; then block "is a force push." fi if echo "$COMMAND" | grep -qE '(^|[[:space:]&|;(])git[[:space:]]+push([^&|;]*[[:space:]:/])(refs/heads/)?(master|main)([[:space:]&|;:]|$)'; then @@ -24,7 +24,6 @@ DANGEROUS_PATTERNS=( "git reset --hard" "git clean -fd" "git clean -f" - "git branch -D" "git checkout \." "git restore \." "reset --hard"