fix(release): spawn npm.cmd with shell:true in prepare-root-publish too (#3348)

Same EINVAL bug as #3346 (stage-internal-runtime-bundles.mjs's runBuild),
one file over: prepare-root-publish.mjs's own npm.cmd spawnSync for
building v3/@claude-flow/swarm and cli lacked shell:true, blocking the
root claude-flow package's Windows publish the same way. Found
immediately after #3346 while publishing 3.42.3 end to end.

Single-string shell:true form, matching #3346's fix, to avoid Node's
DEP0190 warning. Still constant literals, no injection surface.
This commit is contained in:
rUv
2026-09-16 16:36:46 +00:00
committed by GitHub
parent fcee45bc1d
commit 6f0ed71128
+9 -5
View File
@@ -42,15 +42,19 @@ if (result.status !== 0) {
const cliDirectory = resolve(repoRoot, 'v3', '@claude-flow', 'cli');
await stageInternalRuntimeBundles(cliDirectory);
const npmCommand = process.platform === 'win32' ? 'npm.cmd' : 'npm';
// CreateProcess cannot launch a .cmd directly, and Node has refused to
// implicitly shell out to one since CVE-2024-27980 — spawnSync('npm.cmd', ...)
// without shell:true throws EINVAL on Windows (see stage-internal-runtime-
// bundles.mjs's runBuild(), same bug, same fix). command/args here are
// constant literals, never externally derived, so shell:true is safe.
const win32 = process.platform === 'win32';
for (const packageDirectory of [
resolve(repoRoot, 'v3', '@claude-flow', 'swarm'),
cliDirectory,
]) {
const build = spawnSync(npmCommand, ['run', 'build'], {
cwd: packageDirectory,
stdio: 'inherit',
});
const build = win32
? spawnSync('npm.cmd run build', { cwd: packageDirectory, stdio: 'inherit', shell: true })
: spawnSync('npm', ['run', 'build'], { cwd: packageDirectory, stdio: 'inherit' });
if (build.error) throw build.error;
if (build.status !== 0) {
throw new Error(