mirror of
https://github.com/willmiao/ComfyUI-Lora-Manager.git
synced 2026-10-06 01:45:31 -03:00
chore(registry): trim the published archive to runtime files
The registry security scan flags a node version on ANY finding, even severity "info", so every file in node.zip is scan surface. Dev-only trees (tests/, docs/, scripts/, .agents/, Vue widget sources) accounted for ~44 of the 115 findings that flagged 1.2.2-1.2.4. comfy-cli builds the archive as `git ls-files` minus `.comfyignore` matches, so this drops 501 of 1033 tracked files while keeping every runtime path: py/, web/, static/, templates/, locales/, example_workflows/, data/supporters.json, refs/, standalone.py. Dropping vue-widgets/ is deliberate: the prebuilt bundle ships in web/comfyui/vue-widgets/, and py/vue_widget_builder.py skips its mtime check when src/ is absent, so end-user installs no longer risk an npm install at startup.
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
# .comfyignore — keep the Comfy Registry archive to runtime-only files.
|
||||
#
|
||||
# comfy-cli builds node.zip as: git-tracked files − .comfyignore matches
|
||||
# + [tool.comfy].includes (we declare none). Patterns use .gitignore
|
||||
# (gitwildmatch) syntax, evaluated against paths relative to the repo root.
|
||||
# https://docs.comfy.org/registry/publishing
|
||||
#
|
||||
# Why this file exists: the registry security scan flags a version on ANY
|
||||
# finding, even severity "info", so every shipped file is scan surface.
|
||||
# Dev-only files (tests, docs, tooling scripts, agent notes, Vue sources)
|
||||
# accounted for ~44 of the 115 findings that flagged 1.2.2–1.2.4.
|
||||
|
||||
# Test suites
|
||||
/tests/
|
||||
|
||||
# Developer documentation, plans and internal notes
|
||||
/docs/
|
||||
/.omo/
|
||||
/.specs/
|
||||
/AGENTS.md
|
||||
/update_logs.md
|
||||
|
||||
# Agent skill definitions (repo tooling, not loaded by ComfyUI)
|
||||
/.agents/
|
||||
|
||||
# CI and repository automation
|
||||
/.github/
|
||||
|
||||
# Repository tooling scripts — maintenance only, never imported at runtime.
|
||||
# scripts/api.js + scripts/app.js are ComfyUI stubs consumed by the vitest suite.
|
||||
/scripts/
|
||||
|
||||
# Vue widget sources and build inputs. The prebuilt bundle that actually ships
|
||||
# lives in web/comfyui/vue-widgets/. Dropping the sources also stops the startup
|
||||
# auto-builder from running its mtime check (and an npm install) on end-user
|
||||
# machines, since py/vue_widget_builder.py skips the check when src/ is absent.
|
||||
/vue-widgets/
|
||||
|
||||
# Root npm tooling — frontend test runner only
|
||||
/package.json
|
||||
/package-lock.json
|
||||
/vitest.config.js
|
||||
/pytest.ini
|
||||
/requirements-dev.txt
|
||||
|
||||
# Sourcemaps are build artifacts, never loaded at runtime
|
||||
web/comfyui/vue-widgets/*.js.map
|
||||
|
||||
# Keep this file itself out of the archive
|
||||
/.comfyignore
|
||||
Reference in New Issue
Block a user