mirror of
https://github.com/JuliusBrussee/caveman.git
synced 2026-08-11 13:21:09 +02:00
Marketplace fix (#712, #705): Claude Desktop rejects plugins containing a top-level bin/ directory, and .claude-plugin/marketplace.json packages the repo root, so the installer directory is now cli/. Every reference updated (package.json bin entry + files, shims, docs, tests, caveman-init require path). Supersedes PR #726. Security (PR #717 verified): quoteWinArg only quoted on whitespace/quotes, leaving cmd.exe metacharacters (& | ^ < > % parens) unescaped on the shell:true Windows spawn path. Attacker-influenced arguments (--with-init cwd, --with-mcp-shrink value) could chain commands. Trigger regex now covers the metacharacter set; quoting logic split into a platform- independent, unit-tested helper. Also: - uninstall removes .caveman-active.prev, .caveman-mode-log.jsonl, .caveman-statusline-suffix, .caveman-nudge-shown; keeps .caveman-history.jsonl with a printed note; dry-run now says 'would remove' instead of lying (#635, supersedes PRs #693 #636) - Array.isArray guard in rewriteLegacyManagedHookCommands — malformed hook event no longer crashes the installer mid-run (supersedes PR #646) - gemini extensions install --consent: the security prompt hung every piped/non-interactive install forever (#676, part of PR #664) - OpenClaw skill stamps the real PINNED_REF version instead of hardcoded 1.0.0; new --no-always flag for load-on-demand installs (supersedes PR #720) - shims scope NPM_CONFIG_ALLOW_GIT=all to the npx call — npm >=12 defaults allow-git to none and EALLOWGITs github: installs (#698) - .codex/config.toml ships hooks + codex_hooks keys so auto-activation works on both sides of the codex-cli rename (#617) - caveman-help card shows the Windows config path (%APPDATA%) (#723) - caveman-parse.js added to HOOK_FILES, opencode payload (.cjs), and the regenerated checksums.sha256; manifest now matches shipped hook contents — release must bump PINNED_REF to a tag containing these files Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016ySX6TBWZuvFze4ajf7Hpf
57 lines
2.2 KiB
Bash
Executable File
57 lines
2.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# caveman — installer shim.
|
|
#
|
|
# Thin wrapper around cli/install.js (the unified Node installer). Every flag
|
|
# you'd pass to cli/install.js can be passed here; we just forward them.
|
|
#
|
|
# One-line install:
|
|
# curl -fsSL https://raw.githubusercontent.com/JuliusBrussee/caveman/main/install.sh | bash
|
|
# curl -fsSL https://raw.githubusercontent.com/JuliusBrussee/caveman/main/install.sh | bash -s -- --all
|
|
#
|
|
# Local clone:
|
|
# bash install.sh [flags]
|
|
#
|
|
# Why a Node installer? install.sh + install.ps1 used to be parallel sources
|
|
# of truth and constantly drifted (issue #249, etc.). One Node script works
|
|
# everywhere without bash/PowerShell quoting bugs.
|
|
|
|
set -euo pipefail
|
|
|
|
REPO="JuliusBrussee/caveman"
|
|
|
|
# Require Node ≥18. nvm is a common path; print a hint if missing.
|
|
if ! command -v node >/dev/null 2>&1; then
|
|
echo "caveman: Node.js (≥18) required. Install:" >&2
|
|
echo " macOS: brew install node" >&2
|
|
echo " Linux: see https://nodejs.org or use nvm (https://github.com/nvm-sh/nvm)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
NODE_MAJOR=$(node -p "process.versions.node.split('.')[0]")
|
|
if [ "$NODE_MAJOR" -lt 18 ]; then
|
|
echo "caveman: Node $NODE_MAJOR too old. Need Node ≥18." >&2
|
|
echo " Upgrade: https://nodejs.org" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# If we're inside the repo clone, run the local installer directly — saves
|
|
# the npx round-trip and keeps offline installs working. BASH_SOURCE is unset
|
|
# when bash is invoked from stdin (curl | bash), and `set -u` would trip on a
|
|
# bare reference — default to empty so the curl-pipe path falls through cleanly.
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]:-}")" 2>/dev/null && pwd)" || here=""
|
|
if [ -n "$here" ] && [ -f "$here/cli/install.js" ]; then
|
|
exec node "$here/cli/install.js" "$@"
|
|
fi
|
|
|
|
# Curl-pipe path: delegate to npx. We do NOT pass `--` here — npm 7+ npx
|
|
# already forwards trailing args to the package, and a literal `--` tripped
|
|
# cli/install.js's parseArgs as an unknown flag.
|
|
if ! command -v npx >/dev/null 2>&1; then
|
|
echo "caveman: npx required (ships with Node ≥18). Reinstall Node.js." >&2
|
|
exit 1
|
|
fi
|
|
|
|
# npm >=12 defaults allow-git to "none", failing github: specs with EALLOWGIT
|
|
# (#698). Scope the override to this one invocation.
|
|
NPM_CONFIG_ALLOW_GIT=all exec npx -y "github:$REPO" "$@"
|