Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Checked-in generated files are only a snapshot of an earlier generator run. To verify they still match today’s source and configuration, rerun the generator in CI and compare its output with the commit being tested. A successful compile alone cannot prove generated output is current.

Why committed generated files can become stale

A schema or other source can change while its generated output remains untouched. That old output may still compile, so a passing build does not necessarily show that the repository reflects the current source. For example, changing or reusing a Protocol Buffers field without rerunning buf generate can leave generated code behind the schema.

The reliable check is to run the same generator against the committed inputs and verify that it produces exactly the files already in the commit. This tests reproducibility of the checked-in output, rather than merely whether the current output happens to build.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Write a careful check for one generator

For a generated directory that contains only generated files, a shell check can remove that directory, regenerate it, compare tracked changes with HEAD, and detect any newly created untracked files:

set -eu
rm -rf path/to/generated
buf generate
git diff --exit-code HEAD -- path/to/generated
test -z "$(git ls-files --others --exclude-standard -- path/to/generated)"

Replace path/to/generated and buf generate with the actual output path and generator command. The removal is deliberate: it ensures the check does not preserve files that the generator no longer emits. The diff checks whether tracked output differs from the commit, while the final command catches newly generated files that Git does not yet track.

Comparing with HEAD makes the check about the commit CI has checked out. A comparison limited to the index can answer a different question if the working tree or index has additional changes.

Keep cleanup inside an exclusively generated directory

Do not recursively remove a directory that also contains handwritten files. Either direct generated output to a dedicated directory or use a generator configuration that leaves the mixed directory intact. In genguard’s example configuration, clean: true is used for an exclusively generated directory and clean: false where handwritten files coexist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a plain diff can miss

  • New output: A generator may create files that Git has not tracked yet. A normal tracked-file diff does not necessarily report them, so check for untracked files in the declared output path.
  • Obsolete output: A generator may stop producing a file that remains tracked in the repository. If the old file is left in place, it can remain unchanged and escape a diff. Regenerating into a clean output directory exposes that leftover.

These checks assume the generator’s declared output path is accurate. Files outside that path are not covered by a path-limited comparison.

Run the check without disturbing a developer’s checkout

Deleting generated files and rerunning commands directly in a working tree can leave local changes behind, or risk deleting handwritten content if the cleanup path is too broad. A safer option for a local verification workflow is an isolated temporary worktree. genguard documents an --isolated mode for running in a temporary worktree so the original checkout is left alone.

In CI, use a disposable checkout or otherwise ensure cleanup is confined to generated-only output. The generator’s working directory, declared outputs, and cleanup behavior should be explicit rather than inferred from a broad repository-wide deletion.

Pin and install the generator used by CI

Generator versions can affect output. If a developer generates files with one version and CI uses another, a drift check may report differences even when the source has not changed. Pin the expected version and arrange for the CI job to put the generator binary on PATH.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

genguard can run configured generator commands and fail when their declared outputs differ from HEAD. It supports declared tool versions and grouped inputs and outputs, but it does not fetch or install the generators, and it does not commit regenerated changes. The CI environment remains responsible for installing tools, and a failing check means the output needs attention rather than an automatic commit.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When genguard fits—and what it cannot guarantee

A configuration-driven check can be useful when a repository has multiple generators, distinct input/output groups, or needs a consistent way to run declared commands. Its value is operational: it organizes checks against configured outputs. The available source does not establish that it is universally better than a short hand-written CI script.

Before adopting it, verify its current documentation and release details. A source published October 1, 2026 describes genguard v0.7.0 and calls the project pre-1.0; it also notes that flags had changed before. Those are dated details, not a guarantee of the current release or CLI. The same source says genguard only checks declared output paths and cannot make an inherently non-bit-stable generator produce identical results on every run.

Make selective checks account for outputs as well as inputs

Skipping generation when “nothing relevant changed” sounds efficient, but a changed-path filter can miss necessary runs if it watches only source inputs. A robust skip decision should consider:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Changes to declared input paths and generated output paths.
  • Changes to generator configuration or other files that affect its command.
  • Missing declared outputs, which may require regeneration even without a relevant source diff.
  • Untracked files in output paths.

When those conditions are difficult to model safely, running the generator check on every relevant CI run is simpler than relying on an incomplete filter.

A practical CI checklist

  • Run the generator from the same source revision CI is validating.
  • Pin the generator version and install it explicitly in the job.
  • Clean only directories that contain generated files exclusively.
  • Compare generated output with HEAD.
  • Check for untracked generated files and remove stale tracked output by regenerating into a clean destination.
  • Declare the complete output paths, and test any selective-run logic against configuration changes and missing files.
  • Use an isolated worktree or disposable checkout when cleanup could alter a developer’s working tree.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.