mirror of
https://github.com/ruvnet/ruflo.git
synced 2026-09-28 06:22:58 +08:00
fix(release): spawn npm.cmd with shell:true in prepare-root-publish too (#3348)
Same EINVAL bug as #3346 (stage-internal-runtime-bundles.mjs's runBuild), one file over: prepare-root-publish.mjs's own npm.cmd spawnSync for building v3/@claude-flow/swarm and cli lacked shell:true, blocking the root claude-flow package's Windows publish the same way. Found immediately after #3346 while publishing 3.42.3 end to end. Single-string shell:true form, matching #3346's fix, to avoid Node's DEP0190 warning. Still constant literals, no injection surface.
This commit is contained in:
@@ -42,15 +42,19 @@ if (result.status !== 0) {
|
||||
const cliDirectory = resolve(repoRoot, 'v3', '@claude-flow', 'cli');
|
||||
await stageInternalRuntimeBundles(cliDirectory);
|
||||
|
||||
const npmCommand = process.platform === 'win32' ? 'npm.cmd' : 'npm';
|
||||
// CreateProcess cannot launch a .cmd directly, and Node has refused to
|
||||
// implicitly shell out to one since CVE-2024-27980 — spawnSync('npm.cmd', ...)
|
||||
// without shell:true throws EINVAL on Windows (see stage-internal-runtime-
|
||||
// bundles.mjs's runBuild(), same bug, same fix). command/args here are
|
||||
// constant literals, never externally derived, so shell:true is safe.
|
||||
const win32 = process.platform === 'win32';
|
||||
for (const packageDirectory of [
|
||||
resolve(repoRoot, 'v3', '@claude-flow', 'swarm'),
|
||||
cliDirectory,
|
||||
]) {
|
||||
const build = spawnSync(npmCommand, ['run', 'build'], {
|
||||
cwd: packageDirectory,
|
||||
stdio: 'inherit',
|
||||
});
|
||||
const build = win32
|
||||
? spawnSync('npm.cmd run build', { cwd: packageDirectory, stdio: 'inherit', shell: true })
|
||||
: spawnSync('npm', ['run', 'build'], { cwd: packageDirectory, stdio: 'inherit' });
|
||||
if (build.error) throw build.error;
|
||||
if (build.status !== 0) {
|
||||
throw new Error(
|
||||
|
||||
Reference in New Issue
Block a user