Auto Git (AutoGit-AI)
A VS Code extension that automatically stages, commits, and pushes your changes with AI-generated commit messages using GitHub Copilot.
✨ Features
- 🔐 Built-in Secret Scanning: Every commit's staged diff is scanned for API keys, tokens, private keys, and hardcoded passwords before it happens — on by default, zero configuration (why this matters)
- 🤖 AI-Powered Commit Messages: Uses GitHub Copilot to generate meaningful, contextual commit messages from your file list and a diff summary
- 🔄 Automatic Git Operations: Automatically stages, commits, and (optionally) pushes changes when files change
- 🎯 Smart File Filtering: Gitignore-style exclude patterns that work correctly on Windows, macOS, and Linux
- 🛡️ Protected Branches: Skip auto-commits on branches you designate (e.g.
main)
- ⏱️ Configurable Delays: Debounces commits to batch related changes together
- 🎮 Manual Override: Toggle auto-commit on/off or trigger immediate commits
- 📊 Status Bar Integration: See current status and control the extension from the status bar
- 📜 Output Channel Logging: Full timestamped logs in the "Auto Git" output channel
- ⚙️ Highly Configurable: Push behavior, AI usage, notification noise, and more
📋 Prerequisites
- Git: Installed and configured (
user.name / user.email)
- GitHub Copilot (optional but recommended): Needed for AI commit messages; without it the extension writes descriptive fallback messages
- Git Repository: Your workspace must be a git repository (a remote is required only if
autoPush is enabled)
- VS Code 1.90+
🚀 Installation
Option 1: Install from VSIX
- Download the
.vsix file
- Open VS Code → Extensions view (
Ctrl+Shift+X)
- Click the
... menu and select Install from VSIX...
Option 2: Build from Source
git clone https://github.com/Sonica-B/AutoGit.git
cd AutoGit
npm install
npm test
npx @vscode/vsce package
code --install-extension auto-git-copilot-*.vsix
📖 Usage
- Enable Auto Git: Click the status bar item "Auto Git: OFF", or run Auto Git: Toggle Auto Git from the command palette (
Ctrl+Shift+P)
- Save files: After the configured delay the extension stages changes (respecting exclude patterns), generates a commit message, commits, and pushes (if
autoPush is on)
- Manual commit: Run Auto Git: Commit Changes Now to skip the delay
- Watch it work: Run Auto Git: Show Logs to see every git command and decision
🎯 Commands
| Command |
Description |
Auto Git: Toggle Auto Git |
Enable/disable automatic git operations |
Auto Git: Enable Auto Git |
Turn auto-commit on |
Auto Git: Disable Auto Git |
Turn auto-commit off |
Auto Git: Commit Changes Now |
Immediately commit current changes without waiting |
Auto Git: Show Logs |
Open the Auto Git output channel |
📊 Status Bar Indicators
Auto Git: OFF (orange) — auto-commit disabled; click to enable
Auto Git: ON — enabled and watching for changes
Auto Git: Pending (n) — n changed files queued, waiting out the delay
Auto Git: Working... — staging, committing, pushing
⚙️ Configuration
Search for "Auto Git" in VS Code settings:
| Setting |
Type |
Default |
Description |
autoGitCopilot.enabled |
boolean |
false |
Enable automatic git operations |
autoGitCopilot.delayMs |
number |
3000 |
Debounce delay (1000–30000 ms) before committing |
autoGitCopilot.autoPush |
boolean |
true |
Push after each commit; disable to commit locally only |
autoGitCopilot.includeUntracked |
boolean |
true |
Include untracked files in commits |
autoGitCopilot.useAI |
boolean |
true |
Use Copilot for commit messages (falls back automatically if unavailable) |
autoGitCopilot.scanForSecrets |
boolean |
true |
Block commits whose staged diff contains credential patterns |
autoGitCopilot.secretScanIgnorePatterns |
array |
[] |
Regexes matched against a finding's text or file:line to suppress it |
autoGitCopilot.maxCommitMessageLength |
number |
72 |
Maximum commit message length (20–200) |
autoGitCopilot.protectedBranches |
array |
[] |
Branches on which auto-commit is skipped, e.g. ["main"] |
autoGitCopilot.notificationLevel |
string |
"errors" |
Popup noise: "all", "errors", or "none" |
autoGitCopilot.excludePatterns |
array |
see below |
Glob patterns excluded from auto-commit |
Exclude Patterns
Patterns follow gitignore-style semantics:
* matches within one path segment (*.log → error.log, logs/error.log)
** matches across segments (dist/** → everything under dist/)
- A pattern with an interior
/ (or a leading /) is anchored to the workspace root; a bare name — including a trailing-slash directory like build/ — matches at any depth
- Windows backslash paths are handled automatically
Default excludes: node_modules/**, .git/**, *.log, .env*, dist/**, build/**, out/**, *.tmp, *.temp, .DS_Store, Thumbs.db, *.vsix, .vscode-test/**, coverage/**, *.lock, package-lock.json
Example
{
"autoGitCopilot.enabled": true,
"autoGitCopilot.delayMs": 5000,
"autoGitCopilot.autoPush": false,
"autoGitCopilot.protectedBranches": ["main", "release"],
"autoGitCopilot.notificationLevel": "all"
}
🔐 Secret Scanning
Auto-commit removes the human review step between saving a file and pushing it — which is exactly when secrets leak. In 2025, 28.65 million hardcoded secrets hit public GitHub (+34% YoY), and AI-assisted commits leak at roughly twice the baseline rate (GitGuardian, State of Secrets Sprawl 2026).
AutoGit therefore scans every staged diff before committing:
- What it detects: AWS/GitHub/GitLab/Google/Slack/Stripe/npm/SendGrid/OpenAI/Anthropic keys and tokens, JWTs, private-key blocks, connection strings with embedded passwords, and entropy-checked generic assignments (
password = "...", api_key = "...")
- What happens on a hit: the commit is blocked, findings are logged with redacted previews (the secret is never echoed), and a warning notification appears — regardless of your
notificationLevel
- Fails closed: if the staged change is too large to scan safely, the commit is also blocked (not silently allowed) until you confirm
- Escape hatches:
- Click Commit Anyway on the notification. The override is bound to the exact content you reviewed (by fingerprint) — if the staged change is different next time, it is scanned again, so a stale click can never leak a new secret.
- Add a regex to
autoGitCopilot.secretScanIgnorePatterns (matched against the finding text or its file:line; suppressions are logged, and unsafe/ReDoS-prone patterns are rejected)
- Append
autogit:allow-secret in a comment on the flagged line (e.g. for documentation examples)
- Detects unquoted secrets too:
.env, INI, and YAML assignments (DB_PASSWORD=…, aws_secret_access_key = …) are caught, not just quoted code literals
- Limits: findings are capped at 50 per run; placeholder values (
${VAR}, <your-key>, changeme, process.env...) are filtered to avoid false positives
Scanning only inspects lines added by the pending commit, so pre-existing history is untouched. Detection is pattern + entropy heuristics — it reduces risk substantially but is not a guarantee; keep secrets in environment variables or a secret manager.
Exclusions are enforced at commit time
Files matching excludePatterns are never staged, even when an included file triggers the run — the extension stages an explicit, filtered path list rather than a blanket git add .. So a .env, dist/ bundle, or *.log that isn't in .gitignore still won't be auto-committed.
Safe around in-progress git operations
Auto-commit is skipped (with a notification) while a merge, rebase, cherry-pick, or revert is in progress, and when HEAD is detached — so conflict markers and orphan commits are never auto-committed or pushed. Operations are scoped to your workspace folder, so a workspace that is a subdirectory of a larger repo never sweeps in unrelated changes.
🤖 AI Commit Messages
When Copilot is available, the extension sends it the changed-file list plus a truncated git diff --cached --stat summary and asks for a conventional-commit-style, single-line message:
feat: add user authentication system
fix: resolve login validation issue
docs: update API documentation
If Copilot is unavailable (or useAI is off), a deterministic fallback is used:
chore: update src/app.js (single file)
chore: add 1, update 2 files (multiple files)
AI requests time out after 20 seconds, so a slow model never blocks your commit.
💡 Best Practices
- Review before enabling on important repositories — auto-commit is a workflow tool, not a substitute for curated history
- Protect your main branch:
"autoGitCopilot.protectedBranches": ["main"]
- Exclude secrets and artifacts: extend
excludePatterns for anything sensitive (note: .gitignore is always respected by git itself)
- Tune the delay so related edits batch into one commit
- Use commit-only mode (
"autoPush": false) when working offline or when you want to review before pushing
🔧 Troubleshooting
Extension not committing:
- Check the status bar shows
Auto Git: ON
- Run Auto Git: Show Logs — every decision (including excluded files) is logged
- Verify the workspace is a git repository
No AI commit messages:
- Ensure GitHub Copilot is installed, signed in, and active
- Look for "Using language model:" in the logs; "using fallback commit message" means Copilot wasn't reachable
- Requires VS Code 1.90+
Push failures:
- On the first push of a branch the extension sets the upstream automatically, using
remote.pushDefault, or the sole remote, preferring one named origin
- Check credentials (
git push from a terminal should succeed)
- Set
"autoGitCopilot.autoPush": false to commit locally only
Commits on the wrong branch:
- Add branches to
autoGitCopilot.protectedBranches
🧪 Development
npm install # install dev dependencies
npm run lint # ESLint
npm test # unit tests (node:test, no extra dependencies)
npm run check # syntax check all entry points
npx @vscode/vsce package # build the VSIX
Press F5 in VS Code to launch an Extension Development Host. Pure logic lives in lib/ (fully unit-tested); VS Code wiring lives in extension.js.
CI (GitHub Actions) lints, tests, and packages the VSIX on every push and pull request.
🔒 Security
- Git commands are executed with argument arrays (
execFile) — commit messages are never interpolated into a shell string
- Only your existing git configuration and credentials are used
- No data is collected or transmitted by the extension itself; commit message generation goes through the VS Code Language Model API (Copilot)
📄 License
Apache-2.0 — see LICENSE.
📝 Changelog
See CHANGELOG.md for the full version history.
Made with ❤️ for developers who love automation and clean commit histories!