ISSUE COMMANDS
The swamp issue command group interacts with swamp-club Lab issues directly
from the CLI.
swamp issue search [query]
Search or list swamp-club Lab issues.
swamp issue search [query]| Argument | Required | Description |
|---|---|---|
query |
No | Search query |
| Flag | Description |
|---|---|
--type <type> |
Filter by issue type: bug, feature, security |
--status <stat> |
Filter by status: open, triaged, in_progress, shipped, closed |
--source <tag> |
Filter by source tag |
--limit <n> |
Maximum results |
swamp issue get <number>
Fetch and display details of a swamp-club Lab issue.
swamp issue get <number>| Argument | Required | Description |
|---|---|---|
number |
Yes | Issue number |
swamp issue edit <number>
Edit the title or body of an issue.
swamp issue edit <number>| Argument | Required | Description |
|---|---|---|
number |
Yes | Issue number |
| Flag | Description |
|---|---|
-t, --title |
New title (skips editor for title) |
-b, --body |
New body (requires --title, skips editor entirely) |
--type <type> |
Change issue type: bug, feature, security (see restrictions) |
--no-redact |
Skip automatic redaction — see Redaction |
Changing to security is a one-way door — only admins can change the type back.
Setting type to platform is admin-only.
swamp issue bug
Submit a bug report.
swamp issue bug| Flag | Description |
|---|---|
-t, --title |
Bug report title |
-b, --body |
Bug report body (requires --title, skips editor) |
-e, --email |
Open email client with pre-filled bug report (mutually exclusive with --extension) |
-x, --extension |
Route the report against a specific extension (e.g., @adam/cfgmgmt; mutually exclusive with --email) |
--repo-dir <dir> |
Repository directory (env: SWAMP_REPO_DIR); only used with --extension |
--no-redact |
Skip automatic redaction — see Redaction |
swamp issue feature
Submit a feature request.
swamp issue feature| Flag | Description |
|---|---|
-t, --title |
Feature request title |
-b, --body |
Feature request body (requires --title, skips editor) |
-e, --email |
Open email client with pre-filled feature request (mutually exclusive with --extension) |
-x, --extension |
Route the request against a specific extension (mutually exclusive with --email) |
--repo-dir <dir> |
Repository directory (env: SWAMP_REPO_DIR); only used with --extension |
--no-redact |
Skip automatic redaction — see Redaction |
swamp issue security
Submit a security report. Security issues are visible only to the author and admins.
swamp issue security| Flag | Description |
|---|---|
-t, --title |
Security report title |
-b, --body |
Security report body (requires --title, skips editor) |
-e, --email |
Open email client with pre-filled security report (mutually exclusive with --extension) |
-x, --extension |
Route the report against a specific extension (mutually exclusive with --email) |
--repo-dir <dir> |
Repository directory (env: SWAMP_REPO_DIR); only used with --extension |
--no-redact |
Skip automatic redaction — see Redaction |
Automatic classification
Every issue filed with swamp issue bug, swamp issue feature,
swamp issue security, or from the Lab page is classified as it is filed.
Classification can change two fields:
| Field | What can change |
|---|---|
| Type | A bug can become a feature and a feature a bug. Either becomes security when the report describes a vulnerability. A security or platform issue never changes. |
| Source | Set to swamp, swamp-club, extensions, or UAT to match what the issue is about. Any other source value never changes. |
A field changes only when the classifier is confident; otherwise the issue keeps
the value it was filed with. An issue moved to security becomes visible only
to its author and admins.
When classification changes an issue, system posts a ripple listing the new
values. To dispute a classification, ripple on the issue.
Redaction
swamp issue bug, feature, security, edit and ripple redact the title
and body before submission. Redaction runs on every submission path: the Lab,
email (--email), and reports routed to an extension (--extension).
| Category | Matched | Replaced with |
|---|---|---|
| Secret | Credentials in connection strings, NAME=value where the name contains PASSWORD, SECRET, TOKEN, API_KEY, PRIVATE_KEY, ACCESS_KEY or AUTH, AWS access key IDs, GitHub tokens, Bearer tokens, label-prefixed keys (sk_live_…, glpat-…), long hex and mixed-case base64 strings |
[REDACTED-SECRET-N]; [REDACTED-USER]:*** for connection-string credentials |
| Email address | Email addresses | [REDACTED-EMAIL] |
| National ID | XXX-XX-XXXX numbers |
[REDACTED-ID] |
| Credit card | 13–19 digit numbers that pass a Luhn check | [REDACTED-CC] |
| Phone number | Numbers with a + prefix or separators |
[REDACTED-PHONE] |
| Home directory path | The username in /Users/<name>, /home/<name> and C:\Users\<name> |
[REDACTED] |
| IP address | IPv4 and IPv6 addresses, except loopback, link-local and documentation ranges | [IP-N] |
| Hostname | Hosts under internal TLDs (.internal, .local, .lan, .corp, .intranet, .private, .home) and fully qualified domain names with three or more labels |
[HOST-N] |
Public hosts such as github.com, jsr.io, deno.land, swamp-club.com and
example.com are not redacted. Values already masked as *** and shell
references such as ${VAR} are not redacted. Content hashes named by a label
(sha256-…, "checksum": "…") are not redacted.
Numbered placeholders are stable within one submission: the same value maps to the same placeholder everywhere it appears, including across the title and body.
Before submitting, the command prints a summary and each changed line:
Redacted 2 IP addresses, 1 secret, 1 home directory path, 1 hostname from issue content.
title line 1: Connect to 10.20.30.40 fails -> Connect to [IP-1] fails
body line 1: Ran with API_TOKEN=abc123def456 -> Ran with API_TOKEN=[REDACTED-SECRET-1]
body line 2: host 10.20.30.40 at db01.internal -> host [IP-1] at [HOST-1]
body line 3: path /Users/alice/repo -> path /Users/[REDACTED]/repoNothing is printed when no redaction applies. With --json, the notice is
written to stderr as a redaction object carrying message, total and
changes.
--no-redact skips redaction and submits the content as written. The command
prints Redaction skipped (--no-redact); content submitted as written., or
{"redaction":{"skipped":true}} to stderr with --json.
Redaction is pattern-based. It can miss a secret in a format it does not recognise, and it can redact a value that is not sensitive.
swamp issue ripple <number>
Post a comment on an issue. Also available as swamp issue comment.
swamp issue ripple <number>| Argument | Required | Description |
|---|---|---|
number |
Yes | Issue number |
| Flag | Description |
|---|---|
-b, --body |
Ripple body (skips editor) |
--close |
Close the issue after posting |
--reopen |
Reopen the issue after posting |
--no-redact |
Skip automatic redaction — see Redaction |