Summary
Update and metrics suppression uses a manually maintained list and strings.HasPrefix against the command path. Several actual built-ins are absent, while user commands merely beginning with a listed word are treated as built-ins.
Affected code
cmd/root.go:41 — partial builtinCommands list
cmd/root.go:155 — prefix matching
cmd/root.go:327 — registers additional built-ins including login, package, rename, and remote
Impact
Running omitted built-ins can trigger package/self-update checks and metrics unexpectedly. Conversely, user commands such as versioned or update-service can be incorrectly excluded from those behaviors.
Suggested correction
Use Cobra command identity or annotations set when registering built-ins, rather than matching display strings. Keep policy explicit for each built-in and exact for user commands.
Acceptance criteria
- Every registered built-in follows the intended update/metrics policy.
- User commands with built-in-name prefixes are not misclassified.
- Tests cover all built-ins plus prefix-collision user commands.
Summary
Update and metrics suppression uses a manually maintained list and
strings.HasPrefixagainst the command path. Several actual built-ins are absent, while user commands merely beginning with a listed word are treated as built-ins.Affected code
cmd/root.go:41— partialbuiltinCommandslistcmd/root.go:155— prefix matchingcmd/root.go:327— registers additional built-ins including login, package, rename, and remoteImpact
Running omitted built-ins can trigger package/self-update checks and metrics unexpectedly. Conversely, user commands such as
versionedorupdate-servicecan be incorrectly excluded from those behaviors.Suggested correction
Use Cobra command identity or annotations set when registering built-ins, rather than matching display strings. Keep policy explicit for each built-in and exact for user commands.
Acceptance criteria