Skip to content

Commit 5ac6dc5

Browse files
fix(cli): sign every install on upgrade
Installer needs a direct signer because reshim drops nvm.exe errors. Refs #1412 Co-authored-by: Cursor
1 parent 5daab5f commit 5ac6dc5

3 files changed

Lines changed: 10 additions & 2 deletions

File tree

‎src/cmd/main.go‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -102,6 +102,14 @@ func main() {
102102
os.Exit(1)
103103
}
104104
return
105+
case "--sign-installed-versions":
106+
// Installer upgrade from 2.0.0: backfill script trust for every installs\v*.
107+
settings.Load()
108+
if err := verifycache.PrewarmVerifyCache(true); err != nil {
109+
fmt.Fprint(os.Stderr, err.Error())
110+
os.Exit(1)
111+
}
112+
return
105113
case "--sign-version-scripts":
106114
// Invoked by detached reshim after global package installs so proxy
107115
// can trust newly written .cmd/.bat launchers without executing them first.

‎src/commands/env.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -577,7 +577,7 @@ func untrustedHandlerLabel(raw string) string {
577577
// summarizeTrustedModules returns "ALL" when everything is trusted, otherwise
578578
// the count of positive (allow) TrustedModules patterns.
579579
func summarizeTrustedModules(entries []string) string {
580-
rules := modulefirewall.NormalizeList(entries, modulefirewall.DefaultTrustedWhenEmpty)
580+
rules := modulefirewall.NormalizeTrustedModules(entries)
581581
if endpoint, ok := modulefirewall.ExtractHTTPSURL(rules); ok {
582582
return endpoint
583583
}

‎src/commands/env_test.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ func TestSummarizeTrustedModules(t *testing.T) {
1212
entries []string
1313
want string
1414
}{
15-
{name: "empty defaults to zero", entries: nil, want: "0"},
15+
{name: "empty defaults to npm and npx", entries: nil, want: "2"},
1616
{name: "not all alone", entries: []string{"NOT ALL"}, want: "0"},
1717
{name: "all", entries: []string{"ALL"}, want: "ALL"},
1818
{name: "exceptions", entries: []string{"NOT ALL", "opencode", "porthog"}, want: "2"},

0 commit comments

Comments
 (0)