User guide / 사용 안내
English
RepoRun shows evidence before cloning. It is not a terminal, dependency installer, security scanner, or deployment certification tool.
Inspect a project
Extract the Chrome ZIP. In chrome://extensions, enable Developer mode, choose Load unpacked, and select the folder containing manifest.json. With the source ZIP, select dist/. Reload existing GitHub tabs.
Open a GitHub repository and select Run setup below the right-hand About section. If that sidebar is absent, hidden or stacked below the content, use the small blue icon button at the bottom right. RepoRun never adds its control to the repository header action list. RepoRun resolves the default branch to one commit and inspects the root directory. You may enter a relative directory such as apps/web (up to five levels) and choose Inspect. Parent configuration is not inherited and workspaces are not expanded. The commit, scope, inspection time, and cache status are displayed.
Read the evidence
Declared means a field or file was found. Inferred means a limited clue such as a lockfile name. Not established means insufficient evidence. Every source link is pinned to the inspected commit. Overview shows runtime declarations, manager hints, a build script, environment variable names and container clues. Commands shows literal package scripts and a small README sample. Evidence lists supported files and whether they were read, skipped or only detected.
Commands and secrets
Copying a script does not execute it. Package-manager environments and lifecycle hooks may change its behavior. Copy is disabled when a script is redacted, truncated or contains multiline/control text. Environment-example values are not shown. Neither the built-in redaction nor this static inspection proves that a repository is safe.
Authentication and troubleshooting
Public repositories may work without a token. Private repositories need a token authorized for the repository with Contents read permission; organization policies may require approval. RepoRun tokens are independent of RepoDelta and other extensions. Save a token in Settings, then run API diagnostics. A HTTP 200 diagnostic result confirms that request, not permission for every private repository. Token rejection, missing access, API limits, network errors and internal invocation errors are reported separately.
Limits and updates
The default branch is always used, including when another branch is open. A scan reads at most 14 supported regular text files, each at most 128 KiB. It does not read .env, .npmrc, dependency lockfile contents, arbitrary application code or execute JavaScript configuration. Symlinks, submodules and LFS payloads are not followed. Scripts are capped at 40 and environment names at 100; README shell examples at six. Static hosting compatibility is intentionally not certified.
Replace the files in the same unpacked-extension directory and reload the extension to update. Session tokens and cached reports are cleared on reload. Re-enter a token when needed. Store submission, policy hosting and GitHub publishing are separate actions.
한국어
RepoRun은 클론 전 근거를 확인하는 도구입니다. 터미널·설치기·보안 스캐너·배포 인증 도구가 아닙니다.
프로젝트 분석
Chrome ZIP을 압축 해제하고 chrome://extensions에서 개발자 모드를 켠 뒤 manifest.json이 있는 폴더를 로드하세요. 소스 ZIP에서는 dist/를 선택합니다. 기존 GitHub 탭은 새로고침합니다.
저장소 우측 About 영역 하단의 실행 조건 버튼을 선택하면 기본 브랜치를 한 커밋에 고정하여 루트를 분석합니다. apps/web처럼 상대 디렉터리(최대 5단계)를 직접 지정할 수 있습니다. 상위 설정 상속과 워크스페이스 자동 확장은 하지 않습니다. 커밋·범위·조회 시각·캐시 상태를 표시합니다. 우측 사이드바가 없거나 숨겨져 있거나 본문 아래에 쌓이는 화면에서는 우측 하단의 작은 블루 아이콘 버튼을 사용합니다. 저장소 상단 액션 영역에는 버튼을 추가하지 않습니다.
근거 읽기
명시됨은 파일에서 확인한 선언, 추정됨은 잠금 파일명 등의 단서, 확인되지 않음은 근거 부족을 뜻합니다. 원문 링크는 모두 분석 커밋에 고정됩니다. 개요에는 런타임·관리자·빌드 선언·환경변수 이름·컨테이너 단서가, 명령 탭에는 패키지 스크립트와 README 예시 일부가 표시됩니다. 근거 파일 탭은 읽음·건너뜀·존재만 확인을 구분합니다.
명령과 민감정보
복사는 실행이 아닙니다. 패키지 관리자의 환경과 생명주기 훅에 따라 동작이 달라질 수 있습니다. 가림·잘림·여러 줄·제어문자가 있는 스크립트는 복사를 제한합니다. 환경변수 예제 값은 표시하지 않습니다. 가림 기능이나 정적 분석은 저장소의 안전성을 보증하지 않습니다.
인증과 문제 해결
공개 저장소는 토큰 없이 사용할 수 있습니다. 비공개 저장소에는 대상 저장소의 Contents 읽기 권한이 있는 토큰이 필요하며 조직 승인이 필요할 수도 있습니다. RepoDelta 등 다른 확장의 토큰과 공유하지 않습니다. 설정에서 저장 후 API 연결 진단을 실행하세요. 진단 HTTP 200은 그 요청의 성공이지 모든 비공개 저장소 접근 보장이 아닙니다. 토큰 거부·권한 부족·API 한도·네트워크·내부 호출 오류를 구분합니다.
범위와 업데이트
다른 브랜치를 보고 있어도 기본 브랜치를 분석합니다. 본문 조회는 최대 14개, 파일당 128 KiB입니다. .env·.npmrc·잠금 파일 본문·임의 앱 코드는 읽지 않으며 JavaScript 설정도 실행하지 않습니다. 심볼릭 링크·서브모듈·LFS 본체는 따라가지 않습니다. 스크립트 40개, 환경변수 100개, README 셸 예시 6개가 상한입니다. 정적 호스팅 호환성은 확정하지 않습니다.
업데이트 시 기존 압축 해제 폴더의 파일을 교체한 뒤 확장을 재로드하세요. 세션 토큰과 캐시는 삭제되므로 필요하면 토큰을 다시 넣습니다. 웹스토어 제출·방침 호스팅·GitHub 반영은 별도 절차입니다.