internal/vaultik/snapshot.go:1150 and internal/vaultik/prune.go:133 show the confirmation prompt only when !opts.Force && !opts.JSON. A prompt on stdout would corrupt the JSON document, and the README already says vaultik prune --json | jq . works as written, with no extra flag. Still, the --force help (internal/cli/snapshot.go:440-443, internal/cli/prune.go:505-506) and the README describe --force as the way to skip the prompt, and --json only as an output format. Nothing tells a user that snapshot remove --json ID deletes without asking.
Found by the second-pass audit on next at e161343.
Definition of done
The --json help text of snapshot remove and prune, and the README's command details for both, say that --json skips the confirmation prompt, as --force does.
make check passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
`internal/vaultik/snapshot.go:1150` and `internal/vaultik/prune.go:133` show the confirmation prompt only when `!opts.Force && !opts.JSON`. A prompt on stdout would corrupt the JSON document, and the README already says `vaultik prune --json | jq .` works as written, with no extra flag. Still, the `--force` help (`internal/cli/snapshot.go:440-443`, `internal/cli/prune.go:505-506`) and the README describe `--force` as the way to skip the prompt, and `--json` only as an output format. Nothing tells a user that `snapshot remove --json ID` deletes without asking.
Found by the second-pass audit on `next` at `e161343`.
## Definition of done
1. The `--json` help text of `snapshot remove` and `prune`, and the README's command details for both, say that `--json` skips the confirmation prompt, as `--force` does.
2. `make check` passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot
self-assigned this 2026-10-07 18:00:19 +02:00
#276 adds to the --json help of snapshot remove and prune, and to their README entries, that --json skips the confirmation prompt, as --force does. Behaviour is unchanged.
Model: opus-5-5
https://git.eeqj.de/sneak/vaultik/pulls/276 adds to the `--json` help of `snapshot remove` and `prune`, and to their README entries, that `--json` skips the confirmation prompt, as `--force` does. Behaviour is unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
internal/vaultik/snapshot.go:1150andinternal/vaultik/prune.go:133show the confirmation prompt only when!opts.Force && !opts.JSON. A prompt on stdout would corrupt the JSON document, and the README already saysvaultik prune --json | jq .works as written, with no extra flag. Still, the--forcehelp (internal/cli/snapshot.go:440-443,internal/cli/prune.go:505-506) and the README describe--forceas the way to skip the prompt, and--jsononly as an output format. Nothing tells a user thatsnapshot remove --json IDdeletes without asking.Found by the second-pass audit on
nextate161343.Definition of done
--jsonhelp text ofsnapshot removeandprune, and the README's command details for both, say that--jsonskips the confirmation prompt, as--forcedoes.make checkpasses.Model: fable-5-1 (audit); opus-5-5 (issue)
#276 adds to the
--jsonhelp ofsnapshot removeandprune, and to their README entries, that--jsonskips the confirmation prompt, as--forcedoes. Behaviour is unchanged.Model: opus-5-5