You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat: keep git operations working when smudge cannot decrypt
- On a missing or wrong key, the smudge filter (both single-shot and
filter-process) now passes the encrypted content through with a clear
warning instead of aborting the checkout, so git pull/checkout/clone
succeed with the file left encrypted
- The warning states the git operation succeeded and how to recover
(envapor init <key>, then envapor decrypt)
- Clean stays fail-closed: encryption failures still abort so plaintext
can never reach the object store
- Also destroy key material in the single-shot smudge/textconv paths
🤖 Generated with Claude Code
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: docs/user-guide.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -374,7 +374,7 @@ Both keys appear in the command by design: migration needs the old key to decryp
374
374
## Troubleshooting
375
375
376
376
**Values look like `ENC[v2:...]` in my editor.**
377
-
The smudge filter did not run on checkout. Run `envapor init --pem <key>` to reinstall the filters, then re-checkout the file with `git checkout -- .env`.
377
+
The file was checked out without being decrypted — either the filters are not installed, or the local key does not match (in that case `git pull`/`git checkout` prints an `envapor: warning: could not decrypt ...` message but completes normally, leaving the file encrypted). Set the correct key with `envapor init <key>`, then run `envapor decrypt` to restore plaintext.
378
378
379
379
**My commit was aborted with a plaintext warning.**
380
380
This is the pre-commit guard doing its job: it caught a value that was not encrypted. Run `envapor doctor` to confirm the filters are installed, then re-stage and commit.
0 commit comments