Git & GitHub

Git workflow

Inspect, stage and commit through RepoTunnel's fixed Git capability surface.

Guides follow the current project source. Check the release notes for your installed version.

Inspection

  • Status
  • Diff
  • Branch/upstream
  • Recent commits

Mutation safeguards

  • Explicit relative staging paths
  • Symlink/protected/secret-bearing path rejection
  • Staged-state and HEAD revalidation
  • Hooks/GPG signing disabled for controlled commit execution

Push

Push remains separate from normal in-project autonomy and requires a current explicit human instruction.

Inspect before publishing

Use RepoTunnel's bounded Git status/diff/log tools. Staging accepts specific project-relative paths, rechecks the live file/index state and blocks protected/secret-bearing content. Committing operates on the exact staged snapshot, not an arbitrary shell command.

Use safe restore-to-HEAD only for eligible files and remember that it still passes the normal history/review boundary.

Publishing is a separate decision

AI Auto permits compatible local edits and commits, but it does not mean the user permanently authorized pushing code. A push must represent the current user's explicit publishing intent and passes a final secret preflight.

Avoid broad force/mirror/delete/all/tags pushes through RepoTunnel's controlled flow. If the user has not requested publication, stop at a locally verified commit.

Know which repository layouts are supported

The approved workspace root must contain its own .git directory. Parent-repository and linked-worktree layouts are rejected because their metadata can live outside the approved root.

Restore-to-HEAD is limited to eligible unstaged, non-conflicted tracked text files and uses the safe-editing path. Staged changes are not silently discarded.

Inspect GitHub connection state

RepoTunnel can broker supported authenticated GitHub work without exposing its credential to the AI shell. A sandboxed command not seeing a token is not proof that GitHub is disconnected.

Keep account/security changes local and check the app’s authoritative connection status.

Start typing to search.