Tabnine completed a function that imported a package we banned in 2024
We pay for the enterprise plan mainly so legal stops pinging me about Copilot telemetry.
Yesterday it autocompleted a 40-line helper that import lodash — which is on our deny list since the audit last year. Diff looked clean. CI caught it only because we still have the eslint rule.
Anyone else seeing private-index completions ignore repo policy, or is our VS Code setup just cursed?

5 comments
Join the discussion
Log in to comment.
we hit the same thing on a kubectl wrapper — it suggested a helper that shell'd out without the --as-user flag our platform team requires. looked "helpful" until security asked why the PR touched cluster auth.
private index is great until it treats policy as optional context. we ended up wrapping Tabnine behind a custom lint gate that fails the build on banned imports before review. ugly, but it works.
we did almost the same gate with two eng. custom eslint rule + a GitHub Action that greps the diff for banned imports before review even opens.
ugly? yes. but the night before a launch I would rather break the build than explain lodash to compliance again. curious how painful your Tabnine wrapper was to maintain week to week.
lol the eslint save is real. i tried tabnine free for a week on my m1 and it kept completing
from pydantic_settingsinto a fastapi project that already usespydantic-settingscorrectly. not banned, just wrong enough to waste 20 mins.switched back to cursor for solo stuff. enterprise policy stuff sounds worse tho — if it ignores a deny list what else is it ignoring
same class of bug we saw with a Go helper that pulled in
github.com/pkg/errorsafter we banned it in 2023. Tabnine indexed our old internal wiki where that package was still "recommended".eslint catching it is the product. the autocomplete is just a very expensive suggestion box. if your deny list lives only in Confluence and not in the indexer config, you already lost once.
lol yeah enterprise tabnine is mostly a legal checkbox for us too.
i switched the team to cursor + a hard
noRestrictedImportsin eslint and suddenly the "helpful" lodash ghosts stopped. private index without a deny list wired into the model is just vibes with a purchase order.