Skip to content

feat(core): support checking a specified dist-tag in checkPkgUpdate - #681

Merged
ikenxuan merged 1 commit into
mainfrom
feat/check-pkg-update-tag
Oct 6, 2026
Merged

ikenxuan merged 1 commit into
mainfrom
feat/check-pkg-update-tag

Conversation

@ikenxuan

@ikenxuan ikenxuan commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

动机

checkPkgUpdate 目前只能对 latest dist-tag 做更新检查。插件走 npm 预发布渠道(beta / rc)分发更新提醒时,推送端能通过 getRemotePkgVersion(name, tag) 拿到渠道最新版本,但引用回复安装环节调用 checkPkgUpdate 只会对比 latest——对安装了 prerelease 的用户恒判「无更新」,渠道化更新流程在这里断掉(即使判出有更新,updatePkg 默认装的也是 latest 正式版,等于降级)。

改动

  • CompareMode 新增可选字段 tag?: string(默认 latest),在 checkPkgUpdate 内透传给 getRemotePkgVersion(name, tag)
  • 指定的 tag 不存在时 npm show 失败,按现有错误路径返回 status: 'error'

兼容性

完全向后兼容:不传 tag 时行为与现状完全一致。

Sourcery 摘要

支持针对选定的 npm dist-tag 检查软件包更新。

新功能:

  • 允许软件包更新检查以指定的 npm dist-tag(例如 beta 或 rc)为目标,同时保留 latest 作为默认值。

增强功能:

  • 当请求的 dist-tag 不可用时,保留现有的错误处理方式。
Original summary in English

Summary by Sourcery

Support checking package updates against a selected npm dist-tag.

New Features:

  • Allow package update checks to target a specified npm dist-tag such as beta or rc while preserving latest as the default.

Enhancements:

  • Preserve existing error handling when the requested dist-tag is unavailable.

Summary by CodeRabbit

  • New Features
    • Package update checks can now target a specified npm dist-tag; checks use latest when no tag is selected.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sourcery-ai

sourcery-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
审阅者指南(小型 PR 中折叠显示)

审阅者指南

checkPkgUpdate 现在支持通过将 opts.tag 转发给 getRemotePkgVersion 来检查调用方指定的 npm dist-tag;省略该选项仍向后兼容现有的 latest 行为,而无效标签则遵循既有的错误处理路径。

支持 dist-tag 的软件包更新检查时序图

sequenceDiagram
    participant Caller
    participant checkPkgUpdate
    participant getPkgVersion
    participant getRemotePkgVersion
    participant npm

    Caller->>checkPkgUpdate: checkPkgUpdate(name, opts)
    checkPkgUpdate->>getPkgVersion: getPkgVersion(name)
    getPkgVersion-->>checkPkgUpdate: local version
    checkPkgUpdate->>getRemotePkgVersion: getRemotePkgVersion(name, opts.tag)
    getRemotePkgVersion->>npm: npm show package@tag
    alt tag exists or tag omitted
        npm-->>getRemotePkgVersion: remote version
        getRemotePkgVersion-->>checkPkgUpdate: remote version
        checkPkgUpdate-->>Caller: update status
    else tag does not exist
        npm-->>getRemotePkgVersion: error
        getRemotePkgVersion-->>checkPkgUpdate: error
        checkPkgUpdate-->>Caller: status: error
    end
Loading

文件级变更

变更 详情 文件
允许软件包更新检查以特定的 npm dist-tag 为目标,同时保留现有的默认行为。
  • 为 CompareMode 添加可选的 tag 配置,其概念上的默认值为 latest。
  • 将配置的标签转发给远程版本查询,从而支持检查 beta 和 rc 等渠道。
  • 当 npm 无法解析指定标签时,沿用现有的错误处理机制。
packages/core/src/utils/system/update.ts

提示和命令

与 Sourcery 交互

  • 触发新的审阅: 在 pull request 中评论 @sourcery-ai review。
  • 继续讨论: 直接回复 Sourcery 的审阅评论。
  • 根据审阅评论生成 GitHub issue: 回复审阅评论,请 Sourcery 根据该评论创建 issue。你也可以使用 @sourcery-ai issue 回复审阅评论,以据此创建 issue。
  • 生成 pull request 标题: 在 pull request 标题的任意位置写入 @sourcery-ai,即可随时生成标题。你也可以在 pull request 中评论 @sourcery-ai title,以随时生成或重新生成标题。
  • 生成 pull request 摘要: 在 pull request 正文的任意位置写入 @sourcery-ai summary,即可在指定位置随时生成 PR 摘要。你也可以在 pull request 中评论 @sourcery-ai summary,以随时生成或重新生成摘要。
  • 生成审阅者指南: 在 pull request 中评论 @sourcery-ai guide,以随时生成或重新生成审阅者指南。
  • 解决所有 Sourcery 评论: 在 pull request 中评论 @sourcery-ai resolve,以解决所有 Sourcery 评论。如果你已经处理完所有评论且不想再看到它们,此功能会很有用。
  • 忽略所有 Sourcery 审阅: 在 pull request 中评论 @sourcery-ai dismiss,以忽略所有现有的 Sourcery 审阅。如果你想从头开始新的审阅,此功能尤其有用——别忘了评论 @sourcery-ai review 来触发新的审阅!

自定义使用体验

访问你的控制面板即可:

  • 启用或禁用审阅功能,例如 Sourcery 生成的 pull request 摘要、审阅者指南等。
  • 更改审阅语言。
  • 添加、移除或编辑自定义审阅说明。
  • 调整其他审阅设置。

获取帮助

Original review guide in English
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

checkPkgUpdate now supports checking a caller-specified npm dist-tag by forwarding opts.tag to getRemotePkgVersion; omitting the option remains backward compatible with the existing latest behavior, while invalid tags follow the established error path.

Sequence diagram for dist-tag-aware package update checks

sequenceDiagram
    participant Caller
    participant checkPkgUpdate
    participant getPkgVersion
    participant getRemotePkgVersion
    participant npm

    Caller->>checkPkgUpdate: checkPkgUpdate(name, opts)
    checkPkgUpdate->>getPkgVersion: getPkgVersion(name)
    getPkgVersion-->>checkPkgUpdate: local version
    checkPkgUpdate->>getRemotePkgVersion: getRemotePkgVersion(name, opts.tag)
    getRemotePkgVersion->>npm: npm show package@tag
    alt tag exists or tag omitted
        npm-->>getRemotePkgVersion: remote version
        getRemotePkgVersion-->>checkPkgUpdate: remote version
        checkPkgUpdate-->>Caller: update status
    else tag does not exist
        npm-->>getRemotePkgVersion: error
        getRemotePkgVersion-->>checkPkgUpdate: error
        checkPkgUpdate-->>Caller: status: error
    end
Loading

File-Level Changes

Change Details Files
Allow package update checks to target a specific npm dist-tag while preserving the existing default behavior.
  • Add optional tag configuration to CompareMode, defaulting conceptually to latest.
  • Forward the configured tag to remote version lookup, allowing channels such as beta and rc to be checked.
  • Rely on the existing error handling when the specified tag cannot be resolved by npm.
packages/core/src/utils/system/update.ts

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 500bfde1-d332-4dd4-b0ca-873c60b0c3c0
📥 Commits

Reviewing files that changed from the base of the PR and between 608a368 and 94bc32b.

📒 Files selected for processing (1)
  • packages/core/src/utils/system/update.ts
 ______________________________________________________________________________________________________________________________________________________________
< Find bugs once. Once a human tester finds a bug, it should be the last time a human tester finds that bug. Automatic tests should check for it from then on. >
 --------------------------------------------------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

你可以通过以下命令安装该版本:

pnpm add https://pkg.pr.new/node-karin@94bc32b -w

@ikenxuan
ikenxuan merged commit df7dcc0 into main Oct 6, 2026
4 of 5 checks passed
@ikenxuan
ikenxuan deleted the feat/check-pkg-update-tag branch October 6, 2026 07:57
@github-actions github-actions Bot mentioned this pull request Oct 6, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

嘿——我发现了 4 个问题

AI Agent 提示词
请处理本次代码审查中的评论:

## 各条评论

### 评论 1
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**调用方标签会执行 Shell 命令**

当调用方提供包含 Shell 语法的标签时,`getRemotePkgVersion` 会将 `opts.tag` 插入传递给 `child_process.exec` 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。

请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。
</issue_to_address>

### 评论 2
<location path="packages/core/src/utils/system/update.ts" line_range="51" />
<code_context>
+   *
+   * @default 'latest'
+   */
+  tag?: string
 }

</code_context>
<issue_to_address>
**带标签的安装使用了错误的版本**

当调用方检查非 latest 标签后调用 `updatePkg(name)`,却没有传递该标签时,`updatePkg` 会使用其默认的 `latest` 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。

请将选定的标签从检查流程传递到更新流程,并将其传递给 `updatePkg`。

另请参见 `packages/core/src/utils/system/update.ts:191`。
</issue_to_address>

### 评论 3
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**预发布版本更新未被发现**

当带标签的预发布版本仅推进其标识符而未改变 `X.Y.Z` 核心版本,并且调用方省略 `compare: 'semver'` 时,`checkPkgUpdate` 会默认为 `xyz`,而 `normalizeStableVersion` 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 `status: 'no'`,调用方因而错过渠道更新。

检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。
</issue_to_address>

### 评论 4
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**缺失的标签会被误认为是更新**

当 `npm show` 成功,但未返回所请求标签的版本时,`getRemotePkgVersion` 会返回空输出。`checkPkgUpdate` 会将其视为不同版本,并报告 `status: 'yes'`,而不是文档所述的 `status: 'error'`。

请验证 `getRemotePkgVersion` 是否返回了版本;如果没有,请报告错误。
</issue_to_address>

Sourcery 对开源项目免费——如果您喜欢我们的审查结果,请考虑分享它们 ✨
Original comment in English

Hey - I've found 4 issues

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Caller tags execute shell commands**

When a caller supplies a tag containing shell syntax, `getRemotePkgVersion` interpolates `opts.tag` into a command passed to `child_process.exec`, so shell metacharacters run arbitrary commands with the application's privileges.

Pass the tag without invoking a shell, or validate and safely escape it before execution.
</issue_to_address>

### Comment 2
<location path="packages/core/src/utils/system/update.ts" line_range="51" />
<code_context>
+   *
+   * @default 'latest'
+   */
+  tag?: string
 }

</code_context>
<issue_to_address>
**Tagged installs use the wrong release**

When a caller checks a non-latest tag and then calls `updatePkg(name)` without passing that tag, `updatePkg` uses its default `latest` tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.

Carry the selected tag from the check through the update flow and pass it to `updatePkg`.

Also at `packages/core/src/utils/system/update.ts:191`.
</issue_to_address>

### Comment 3
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Prerelease updates go unnoticed**

When the tagged prerelease advances its identifier without changing the `X.Y.Z` core and the caller omits `compare: 'semver'`, `checkPkgUpdate` defaults to `xyz`, and `normalizeStableVersion` strips prerelease identifiers before comparison. The versions compare equal, so it returns `status: 'no'` and callers miss the channel update.

Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.
</issue_to_address>

### Comment 4
<location path="packages/core/src/utils/system/update.ts" line_range="191" />
<code_context>
   try {
     const local = await getPkgVersion(name)
-    const remote = await getRemotePkgVersion(name)
+    const remote = await getRemotePkgVersion(name, opts?.tag)

     const mode = opts?.compare ?? 'xyz'
</code_context>
<issue_to_address>
**Missing tags appear as updates**

When `npm show` succeeds but returns no version for the requested tag, `getRemotePkgVersion` returns the empty output, which `checkPkgUpdate` treats as a different version and reports as `status: 'yes'` instead of the documented `status: 'error'`.

Validate that `getRemotePkgVersion` returns a version and report an error when it does not.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨

try {
const local = await getPkgVersion(name)
const remote = await getRemotePkgVersion(name)
const remote = await getRemotePkgVersion(name, opts?.tag)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 严重 · 调用方标签会执行 Shell 命令

当调用方提供包含 Shell 语法的标签时,getRemotePkgVersion 会将 opts.tag 插入传递给 child_process.exec 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。

请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。

AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:

**调用方标签会执行 Shell 命令**

当调用方提供包含 Shell 语法的标签时,`getRemotePkgVersion` 会将 `opts.tag` 插入传递给 `child_process.exec` 的命令中,因此 Shell 元字符会以应用程序的权限执行任意命令。

请在不调用 Shell 的情况下传递该标签,或在执行前对其进行验证并安全转义。
Original comment in English

🔴 Critical · Caller tags execute shell commands

When a caller supplies a tag containing shell syntax, getRemotePkgVersion interpolates opts.tag into a command passed to child_process.exec, so shell metacharacters run arbitrary commands with the application's privileges.

Pass the tag without invoking a shell, or validate and safely escape it before execution.

Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:

**Caller tags execute shell commands**

When a caller supplies a tag containing shell syntax, `getRemotePkgVersion` interpolates `opts.tag` into a command passed to `child_process.exec`, so shell metacharacters run arbitrary commands with the application's privileges.

Pass the tag without invoking a shell, or validate and safely escape it before execution.

*
* @default 'latest'
*/
tag?: string

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 高 · 带标签的安装使用了错误的版本

当调用方检查非 latest 标签后调用 updatePkg(name),却没有传递该标签时,updatePkg 会使用其默认的 latest 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。

请将选定的标签从检查流程传递到更新流程,并将其传递给 updatePkg。

另请参见 packages/core/src/utils/system/update.ts:191。

AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 51 行:

**带标签的安装使用了错误的版本**

当调用方检查非 latest 标签后调用 `updatePkg(name)`,却没有传递该标签时,`updatePkg` 会使用其默认的 `latest` 标签,而不是已检查的渠道。因此,安装会将原本预期的预发布版本替换为稳定版本,并可能导致渠道用户降级。

请将选定的标签从检查流程传递到更新流程,并将其传递给 `updatePkg`。

另请参见 `packages/core/src/utils/system/update.ts:191`。
Original comment in English

🟠 High · Tagged installs use the wrong release

When a caller checks a non-latest tag and then calls updatePkg(name) without passing that tag, updatePkg uses its default latest tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.

Carry the selected tag from the check through the update flow and pass it to updatePkg.

Also at packages/core/src/utils/system/update.ts:191.

Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 51:

**Tagged installs use the wrong release**

When a caller checks a non-latest tag and then calls `updatePkg(name)` without passing that tag, `updatePkg` uses its default `latest` tag instead of the checked channel, so the install replaces the intended prerelease with the stable release and can downgrade channel users.

Carry the selected tag from the check through the update flow and pass it to `updatePkg`.

Also at `packages/core/src/utils/system/update.ts:191`.

try {
const local = await getPkgVersion(name)
const remote = await getRemotePkgVersion(name)
const remote = await getRemotePkgVersion(name, opts?.tag)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 高 · 预发布版本更新未被发现

当带标签的预发布版本仅推进其标识符而未改变 X.Y.Z 核心版本,并且调用方省略 compare: 'semver' 时,checkPkgUpdate 会默认为 xyz,而 normalizeStableVersion 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 status: 'no',调用方因而错过渠道更新。

检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。

AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:

**预发布版本更新未被发现**

当带标签的预发布版本仅推进其标识符而未改变 `X.Y.Z` 核心版本,并且调用方省略 `compare: 'semver'` 时,`checkPkgUpdate` 会默认为 `xyz`,而 `normalizeStableVersion` 会在比较前移除预发布标识符。这样两个版本会被判定为相同,函数会返回 `status: 'no'`,调用方因而错过渠道更新。

检查带标签的预发布版本时,请使用 semver 比较预发布版本,而不要移除预发布标识符。
Original comment in English

🟠 High · Prerelease updates go unnoticed

When the tagged prerelease advances its identifier without changing the X.Y.Z core and the caller omits compare: 'semver', checkPkgUpdate defaults to xyz, and normalizeStableVersion strips prerelease identifiers before comparison. The versions compare equal, so it returns status: 'no' and callers miss the channel update.

Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.

Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:

**Prerelease updates go unnoticed**

When the tagged prerelease advances its identifier without changing the `X.Y.Z` core and the caller omits `compare: 'semver'`, `checkPkgUpdate` defaults to `xyz`, and `normalizeStableVersion` strips prerelease identifiers before comparison. The versions compare equal, so it returns `status: 'no'` and callers miss the channel update.

Compare prerelease versions with semver when checking a tagged prerelease, rather than stripping the prerelease identifiers.

try {
const local = await getPkgVersion(name)
const remote = await getRemotePkgVersion(name)
const remote = await getRemotePkgVersion(name, opts?.tag)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 中 · 缺失的标签会被误认为是更新

当 npm show 成功,但未返回所请求标签的版本时,getRemotePkgVersion 会返回空输出。checkPkgUpdate 会将其视为不同版本,并报告 status: 'yes',而不是文档所述的 status: 'error'。

请验证 getRemotePkgVersion 是否返回了版本;如果没有,请报告错误。

AI Agent 提示词
在 `packages/core/src/utils/system/update.ts` 第 191 行:

**缺失的标签会被误认为是更新**

当 `npm show` 成功,但未返回所请求标签的版本时,`getRemotePkgVersion` 会返回空输出。`checkPkgUpdate` 会将其视为不同版本,并报告 `status: 'yes'`,而不是文档所述的 `status: 'error'`。

请验证 `getRemotePkgVersion` 是否返回了版本;如果没有,请报告错误。
Original comment in English

🟡 Medium · Missing tags appear as updates

When npm show succeeds but returns no version for the requested tag, getRemotePkgVersion returns the empty output, which checkPkgUpdate treats as a different version and reports as status: 'yes' instead of the documented status: 'error'.

Validate that getRemotePkgVersion returns a version and report an error when it does not.

Prompt for AI agents
In `packages/core/src/utils/system/update.ts` at line 191:

**Missing tags appear as updates**

When `npm show` succeeds but returns no version for the requested tag, `getRemotePkgVersion` returns the empty output, which `checkPkgUpdate` treats as a different version and reports as `status: 'yes'` instead of the documented `status: 'error'`.

Validate that `getRemotePkgVersion` returns a version and report an error when it does not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant