Repository navigation
feat(core): support checking a specified dist-tag in checkPkgUpdate - #681
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
审阅者指南(小型 PR 中折叠显示)审阅者指南
支持 dist-tag 的软件包更新检查时序图sequenceDiagram
participant Caller
participant checkPkgUpdate
participant getPkgVersion
participant getRemotePkgVersion
participant npm
Caller->>checkPkgUpdate: checkPkgUpdate(name, opts)
checkPkgUpdate->>getPkgVersion: getPkgVersion(name)
getPkgVersion-->>checkPkgUpdate: local version
checkPkgUpdate->>getRemotePkgVersion: getRemotePkgVersion(name, opts.tag)
getRemotePkgVersion->>npm: npm show package@tag
alt tag exists or tag omitted
npm-->>getRemotePkgVersion: remote version
getRemotePkgVersion-->>checkPkgUpdate: remote version
checkPkgUpdate-->>Caller: update status
else tag does not exist
npm-->>getRemotePkgVersion: error
getRemotePkgVersion-->>checkPkgUpdate: error
checkPkgUpdate-->>Caller: status: error
end
文件级变更
提示和命令与 Sourcery 交互
自定义使用体验访问你的控制面板即可:
获取帮助Original review guide in EnglishReviewer's guide (collapsed on small PRs)Reviewer's Guide
Sequence diagram for dist-tag-aware package update checkssequenceDiagram
participant Caller
participant checkPkgUpdate
participant getPkgVersion
participant getRemotePkgVersion
participant npm
Caller->>checkPkgUpdate: checkPkgUpdate(name, opts)
checkPkgUpdate->>getPkgVersion: getPkgVersion(name)
getPkgVersion-->>checkPkgUpdate: local version
checkPkgUpdate->>getRemotePkgVersion: getRemotePkgVersion(name, opts.tag)
getRemotePkgVersion->>npm: npm show package@tag
alt tag exists or tag omitted
npm-->>getRemotePkgVersion: remote version
getRemotePkgVersion-->>checkPkgUpdate: remote version
checkPkgUpdate-->>Caller: update status
else tag does not exist
npm-->>getRemotePkgVersion: error
getRemotePkgVersion-->>checkPkgUpdate: error
checkPkgUpdate-->>Caller: status: error
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
你可以通过以下命令安装该版本: |
There was a problem hiding this comment.
嘿——我发现了 4 个问题
AI Agent 提示词
请处理本次代码审查中的评论:
## 各条评论
### 评论 1
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**调用方标签会执行 Shell 命令**
当调用方提供包含 Shell 语法的标签时,`getRemotePkgVersion` 会将 `opts.tag` 插入传递给 `child_process.exec` 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。
请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。
</issue_to_address>
### 评论 2
<location path="packages/core/src/utils/system/update.ts" line_range="51" />
<code_context>
+ *
+ * @default 'latest'
+ */
+ tag?: string
}
</code_context>
<issue_to_address>
**带标签的安装使用了错误的版本**
当调用方检查非 latest 标签后调用 `updatePkg(name)`,却没有传递该标签时,`updatePkg` 会使用其默认的 `latest` 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。
请将选定的标签从检查流程传递到更新流程,并将其传递给 `updatePkg`。
另请参见 `packages/core/src/utils/system/update.ts:191`。
</issue_to_address>
### 评论 3
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**预发布版本更新未被发现**
当带标签的预发布版本仅推进其标识符而未改变 `X.Y.Z` 核心版本,并且调用方省略 `compare: 'semver'` 时,`checkPkgUpdate` 会默认为 `xyz`,而 `normalizeStableVersion` 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 `status: 'no'`,调用方因而错过渠道更新。
检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。
</issue_to_address>
### 评论 4
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**缺失的标签会被误认为是更新**
当 `npm show` 成功,但未返回所请求标签的版本时,`getRemotePkgVersion` 会返回空输出。`checkPkgUpdate` 会将其视为不同版本,并报告 `status: 'yes'`,而不是文档所述的 `status: 'error'`。
请验证 `getRemotePkgVersion` 是否返回了版本;如果没有,请报告错误。
</issue_to_address>Original comment in English
Hey - I've found 4 issues
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Caller tags execute shell commands**
When a caller supplies a tag containing shell syntax, `getRemotePkgVersion` interpolates `opts.tag` into a command passed to `child_process.exec`, so shell metacharacters run arbitrary commands with the application's privileges.
Pass the tag without invoking a shell, or validate and safely escape it before execution.
</issue_to_address>
### Comment 2
<location path="packages/core/src/utils/system/update.ts" line_range="51" />
<code_context>
+ *
+ * @default 'latest'
+ */
+ tag?: string
}
</code_context>
<issue_to_address>
**Tagged installs use the wrong release**
When a caller checks a non-latest tag and then calls `updatePkg(name)` without passing that tag, `updatePkg` uses its default `latest` tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.
Carry the selected tag from the check through the update flow and pass it to `updatePkg`.
Also at `packages/core/src/utils/system/update.ts:191`.
</issue_to_address>
### Comment 3
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Prerelease updates go unnoticed**
When the tagged prerelease advances its identifier without changing the `X.Y.Z` core and the caller omits `compare: 'semver'`, `checkPkgUpdate` defaults to `xyz`, and `normalizeStableVersion` strips prerelease identifiers before comparison. The versions compare equal, so it returns `status: 'no'` and callers miss the channel update.
Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.
</issue_to_address>
### Comment 4
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
try {
const local = await getPkgVersion(name)
- const remote = await getRemotePkgVersion(name)
+ const remote = await getRemotePkgVersion(name, opts?.tag)
const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Missing tags appear as updates**
When `npm show` succeeds but returns no version for the requested tag, `getRemotePkgVersion` returns the empty output, which `checkPkgUpdate` treats as a different version and reports as `status: 'yes'` instead of the documented `status: 'error'`.
Validate that `getRemotePkgVersion` returns a version and report an error when it does not.
</issue_to_address>| try { | ||
| const local = await getPkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name, opts?.tag) |
There was a problem hiding this comment.
🔴 严重 · 调用方标签会执行 Shell 命令
当调用方提供包含 Shell 语法的标签时,getRemotePkgVersion 会将 opts.tag 插入传递给 child_process.exec 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。
请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。
AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:
**调用方标签会执行 Shell 命令**
当调用方提供包含 Shell 语法的标签时,`getRemotePkgVersion` 会将 `opts.tag` 插入传递给 `child_process.exec` 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。
请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。Original comment in English
🔴 Critical · Caller tags execute shell commands
When a caller supplies a tag containing shell syntax, getRemotePkgVersion interpolates opts.tag into a command passed to child_process.exec, so shell metacharacters run arbitrary commands with the application's privileges.
Pass the tag without invoking a shell, or validate and safely escape it before execution.
Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:
**Caller tags execute shell commands**
When a caller supplies a tag containing shell syntax, `getRemotePkgVersion` interpolates `opts.tag` into a command passed to `child_process.exec`, so shell metacharacters run arbitrary commands with the application's privileges.
Pass the tag without invoking a shell, or validate and safely escape it before execution.| * | ||
| * @default 'latest' | ||
| */ | ||
| tag?: string |
There was a problem hiding this comment.
🟠 高 · 带标签的安装使用了错误的版本
当调用方检查非 latest 标签后调用 updatePkg(name),却没有传递该标签时,updatePkg 会使用其默认的 latest 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。
请将选定的标签从检查流程传递到更新流程,并将其传递给 updatePkg。
另请参见 packages/core/src/utils/system/update.ts:191。
AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 51 行:
**带标签的安装使用了错误的版本**
当调用方检查非 latest 标签后调用 `updatePkg(name)`,却没有传递该标签时,`updatePkg` 会使用其默认的 `latest` 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。
请将选定的标签从检查流程传递到更新流程,并将其传递给 `updatePkg`。
另请参见 `packages/core/src/utils/system/update.ts:191`。Original comment in English
🟠 High · Tagged installs use the wrong release
When a caller checks a non-latest tag and then calls updatePkg(name) without passing that tag, updatePkg uses its default latest tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.
Carry the selected tag from the check through the update flow and pass it to updatePkg.
Also at packages/core/src/utils/system/update.ts:191.
Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 51:
**Tagged installs use the wrong release**
When a caller checks a non-latest tag and then calls `updatePkg(name)` without passing that tag, `updatePkg` uses its default `latest` tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.
Carry the selected tag from the check through the update flow and pass it to `updatePkg`.
Also at `packages/core/src/utils/system/update.ts:191`.| try { | ||
| const local = await getPkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name, opts?.tag) |
There was a problem hiding this comment.
🟠 高 · 预发布版本更新未被发现
当带标签的预发布版本仅推进其标识符而未改变 X.Y.Z 核心版本,并且调用方省略 compare: 'semver' 时,checkPkgUpdate 会默认为 xyz,而 normalizeStableVersion 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 status: 'no',调用方因而错过渠道更新。
检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。
AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:
**预发布版本更新未被发现**
当带标签的预发布版本仅推进其标识符而未改变 `X.Y.Z` 核心版本,并且调用方省略 `compare: 'semver'` 时,`checkPkgUpdate` 会默认为 `xyz`,而 `normalizeStableVersion` 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 `status: 'no'`,调用方因而错过渠道更新。
检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。Original comment in English
🟠 High · Prerelease updates go unnoticed
When the tagged prerelease advances its identifier without changing the X.Y.Z core and the caller omits compare: 'semver', checkPkgUpdate defaults to xyz, and normalizeStableVersion strips prerelease identifiers before comparison. The versions compare equal, so it returns status: 'no' and callers miss the channel update.
Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.
Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:
**Prerelease updates go unnoticed**
When the tagged prerelease advances its identifier without changing the `X.Y.Z` core and the caller omits `compare: 'semver'`, `checkPkgUpdate` defaults to `xyz`, and `normalizeStableVersion` strips prerelease identifiers before comparison. The versions compare equal, so it returns `status: 'no'` and callers miss the channel update.
Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.| try { | ||
| const local = await getPkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name) | ||
| const remote = await getRemotePkgVersion(name, opts?.tag) |
There was a problem hiding this comment.
🟡 中 · 缺失的标签会被误认为是更新
当 npm show 成功,但未返回所请求标签的版本时,getRemotePkgVersion 会返回空输出。checkPkgUpdate 会将其视为不同版本,并报告 status: 'yes',而不是文档所述的 status: 'error'。
请验证 getRemotePkgVersion 是否返回了版本;如果没有,请报告错误。
AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:
**缺失的标签会被误认为是更新**
当 `npm show` 成功,但未返回所请求标签的版本时,`getRemotePkgVersion` 会返回空输出。`checkPkgUpdate` 会将其视为不同版本,并报告 `status: 'yes'`,而不是文档所述的 `status: 'error'`。
请验证 `getRemotePkgVersion` 是否返回了版本;如果没有,请报告错误。Original comment in English
🟡 Medium · Missing tags appear as updates
When npm show succeeds but returns no version for the requested tag, getRemotePkgVersion returns the empty output, which checkPkgUpdate treats as a different version and reports as status: 'yes' instead of the documented status: 'error'.
Validate that getRemotePkgVersion returns a version and report an error when it does not.
Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:
**Missing tags appear as updates**
When `npm show` succeeds but returns no version for the requested tag, `getRemotePkgVersion` returns the empty output, which `checkPkgUpdate` treats as a different version and reports as `status: 'yes'` instead of the documented `status: 'error'`.
Validate that `getRemotePkgVersion` returns a version and report an error when it does not.
动机
checkPkgUpdate目前只能对latestdist-tag 做更新检查。插件走 npm 预发布渠道(beta / rc)分发更新提醒时,推送端能通过getRemotePkgVersion(name, tag)拿到渠道最新版本,但引用回复安装环节调用checkPkgUpdate只会对比latest——对安装了 prerelease 的用户恒判「无更新」,渠道化更新流程在这里断掉(即使判出有更新,updatePkg默认装的也是 latest 正式版,等于降级)。改动
CompareMode新增可选字段tag?: string(默认latest),在checkPkgUpdate内透传给getRemotePkgVersion(name, tag)npm show失败,按现有错误路径返回status: 'error'兼容性
完全向后兼容:不传
tag时行为与现状完全一致。Sourcery 摘要
支持针对选定的 npm dist-tag 检查软件包更新。
新功能:
增强功能:
Original summary in English
Summary by Sourcery
Support checking package updates against a selected npm dist-tag.
New Features:
Enhancements:
Summary by CodeRabbit
latestwhen no tag is selected.