diff --git a/CHANGELOG.md b/CHANGELOG.md index 64c0ea940..79baa9c65 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -23,6 +23,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Ensure `@tailwindcss/oxide` falls back to WASM on platforms without native bindings ([#20383](https://github.com/tailwindlabs/tailwindcss/pull/20383)) - Detect classes in Ruby percent literals using angle brackets or custom delimiters (e.g. `%w`, `%w|flex|`), including in Slim and Haml templates ([#20387](https://github.com/tailwindlabs/tailwindcss/pull/20387)) - Preserve whitespace in `--default(…)` values in custom functional utilities (e.g. `--default(box alphabetic)` no longer becomes `boxalphabetic`) ([#20392](https://github.com/tailwindlabs/tailwindcss/pull/20392)) +- Don't scan gitignored directories (e.g. `node_modules` and `.git`) when the project uses a safelist-style `.gitignore` (e.g. `/*` followed by `!/…` negations) ([#20397](https://github.com/tailwindlabs/tailwindcss/discussions/20397)) ## [4.3.3] - 2026-07-16 diff --git a/crates/oxide/src/scanner/sources.rs b/crates/oxide/src/scanner/sources.rs index 4a8c6ddf5..53c09387f 100644 --- a/crates/oxide/src/scanner/sources.rs +++ b/crates/oxide/src/scanner/sources.rs @@ -763,12 +763,11 @@ pub fn public_source_entries_to_private_source_entries( .collect::>(); // Compiled `.gitignore` matchers are cached per directory so we read and parse each - // `.gitignore` file at most once, even though entries commonly share ancestor directories - // (e.g. the repository root). A cached `None` means the directory has no `.gitignore` file. + // `.gitignore` file at most once, even though entries commonly share ancestor directories (e.g. + // the repository root). A cached `None` means the directory has no `.gitignore` file. let mut gitignores: FxHashMap> = FxHashMap::default(); - // Boundary for the `.gitignore` walk when a source is not inside a git repository (see - // below). + // Boundary for the `.gitignore` walk when a source is not inside a git repository (see below). let cwd = std::env::current_dir() .map(|cwd| dunce::canonicalize(&cwd).unwrap_or(cwd)) .ok(); @@ -790,18 +789,39 @@ pub fn public_source_entries_to_private_source_entries( let gitignore = gitignores.entry(dir.to_path_buf()).or_insert_with(|| { let path = dir.join(".gitignore"); - // `Gitignore::new` roots the matcher at the directory - // containing the file, so patterns match relative to it. + // `Gitignore::new` roots the matcher at the directory containing the file, + // so patterns match relative to it. path.is_file().then(|| Gitignore::new(&path).0) }); - if let Some(gitignore) = gitignore { - if gitignore - .matched_path_or_any_parents(&base, true) - .is_ignore() - { - source = SourceEntry::External { base: base.into() }; - break; + // Only `.gitignore` files in ancestors of `base` can ignore `base` itself. + // Patterns in `base`'s own `.gitignore` only match paths _inside_ `base`, never + // `base` itself (the file walker still applies them to `base`'s contents). + // + // Skipping `base`'s own `.gitignore` also prevents a false positive for + // whitelist style `.gitignore` files, because relativizing `base` against + // itself yields the empty path, which incorrectly matches `/*`. + // + // E.g.: + // + // ```gitignore + // /* + // !/.gitignore + // !/app + // !/public + // ``` + // + // Everything inside `base` except `.gitignore`, `app` and `public` is ignored, + // but `base` itself is not. + if dir != base { + if let Some(gitignore) = gitignore { + if gitignore + .matched_path_or_any_parents(&base, true) + .is_ignore() + { + source = SourceEntry::External { base: base.into() }; + break; + } } } @@ -810,12 +830,11 @@ pub fn public_source_entries_to_private_source_entries( break; } - // Without a git repository there is no repository root to stop at. Stop - // once the directory contains the current working directory instead, so - // `.gitignore` files outside of the project (e.g. in the user's home - // directory) can never promote a source to an external source. Note that - // the file walker still applies those `.gitignore` files when deciding - // which files to scan. + // Without a git repository there is no repository root to stop at. Stop once + // the directory contains the current working directory instead, so `.gitignore` + // files outside of the project (e.g. in the user's home directory) can never + // promote a source to an external source. Note that the file walker still + // applies those `.gitignore` files when deciding which files to scan. if !inside_git_repo && cwd.as_ref().is_some_and(|cwd| cwd.starts_with(dir)) { break; } diff --git a/crates/oxide/tests/scanner.rs b/crates/oxide/tests/scanner.rs index 2c3ca86b5..f1f3b8bde 100644 --- a/crates/oxide/tests/scanner.rs +++ b/crates/oxide/tests/scanner.rs @@ -1604,6 +1604,107 @@ mod scanner { assert_eq!(normalized_sources, vec!["web/**/*", "web/ignore-1.html"]); } + #[test] + fn it_respects_gitignore_files_with_whitelist_patterns() { + // https://github.com/tailwindlabs/tailwindcss/discussions/20382 + // + // A `.gitignore` that ignores everything (`/*`) and then whitelists specific + // directories and files using negated patterns. + let ScanResult { + files, candidates, .. + } = scan(&[ + ( + ".gitignore", + "/*\n!/app\n!/public\n!/package.json\n!/.gitignore\n", + ), + ("app/index.html", "content-['app/index.html']"), + ("public/index.html", "content-['public/index.html']"), + ("package.json", ""), + // These are all ignored by the `/*` rule because they are not whitelisted + ("build/generated.html", "content-['build/generated.html']"), + ("logs/dev.log", "content-['logs/dev.log']"), + ( + "node_modules/my-ui-lib/index.html", + "content-['node_modules/my-ui-lib/index.html']", + ), + ]); + + assert_eq!( + files, + vec!["app/index.html", "package.json", "public/index.html"] + ); + assert_eq!( + candidates, + vec![ + "content-['app/index.html']", + "content-['public/index.html']" + ] + ); + } + + #[test] + fn it_respects_gitignore_files_with_nested_whitelist_patterns() { + // Example from the official `.gitignore` documentation: + // + // ```gitignore + // # exclude everything except directory foo/bar + // /* + // !/foo + // /foo/* + // !/foo/bar + // ``` + let ScanResult { + files, candidates, .. + } = scan(&[ + ( + ".gitignore", + "# exclude everything except directory foo/bar\n/*\n!/foo\n/foo/*\n!/foo/bar\n", + ), + ("foo/bar/index.html", "content-['foo/bar/index.html']"), + ( + "foo/bar/nested/index.html", + "content-['foo/bar/nested/index.html']", + ), + // These are all ignored because they are not inside `foo/bar` + ("index.html", "content-['index.html']"), + ("foo/index.html", "content-['foo/index.html']"), + ("foo/baz/index.html", "content-['foo/baz/index.html']"), + ]); + + assert_eq!( + files, + vec!["foo/bar/index.html", "foo/bar/nested/index.html"] + ); + assert_eq!( + candidates, + vec![ + "content-['foo/bar/index.html']", + "content-['foo/bar/nested/index.html']" + ] + ); + } + + #[test] + fn explicit_source_directories_respect_their_own_gitignore() { + // A directory referenced via `@source` behaves like an auto source detection + // root. The `.gitignore` file _inside_ that directory still applies to its + // contents. Only when the directory itself is ignored (by an ancestor + // `.gitignore`, see the tests above) do we bypass the ignore rules. + let ScanResult { + files, candidates, .. + } = scan_with_globs( + &[ + ("vendor/.gitignore", "ignored.html"), + ("vendor/index.html", "content-['vendor/index.html']"), + ("vendor/ignored.html", "content-['vendor/ignored.html']"), + ], + vec!["@source 'vendor'"], + ); + + assert_eq!(files, vec!["vendor/index.html"]); + assert_eq!(candidates, vec!["content-['vendor/index.html']"]); + } + #[test] fn explicit_sources_can_include_files_inside_gitignored_parent_directories() { let ScanResult { diff --git a/integrations/cli/index.test.ts b/integrations/cli/index.test.ts index 310086802..07f8bcb68 100644 --- a/integrations/cli/index.test.ts +++ b/integrations/cli/index.test.ts @@ -2276,6 +2276,70 @@ test( }, ) +// https://github.com/tailwindlabs/tailwindcss/discussions/20382 +test( + 'auto source detection respects allow-list .gitignore files', + { + fs: { + 'package.json': json` + { + "dependencies": { + "tailwindcss": "workspace:^", + "@tailwindcss/cli": "workspace:^" + } + } + `, + '.gitignore': txt` + /* + !/.gitignore + !/app + !/public + !/package.json + `, + 'app/root.css': css` @import 'tailwindcss/utilities'; `, + // Included by the `!/app` pattern in `.gitignore` + // + // → Should be included + 'app/index.html': html` +
+ `, + // Included by the `!/public` pattern in `.gitignore` + // + // → Should be included + 'public/index.html': html` +
+ `, + // Ignored by the `/*` in `.gitignore` + // + // → Should be ignored + 'build/index.html': html` +
+ `, + // Ignored by the `/*` in `.gitignore` and the default `node_modules` rules + // + // → Should be ignored + 'node_modules/my-ui-lib/index.html': html` +
+ `, + }, + }, + async ({ fs, exec }) => { + await exec('pnpm tailwindcss --input app/root.css --output dist/out.css') + + await fs.expectFileToContain('dist/out.css', [ + candidate`content-['app/index.html']`, + candidate`content-['public/index.html']`, + ]) + + await fs.expectFileNotToContain('dist/out.css', [ + candidate`content-['build/index.html']`, + candidate`content-['node_modules/my-ui-lib/index.html']`, + ]) + }, +) + test( '@source works with symlinks (referencing folder in current folder)', {