fix(plugins): npm-sourced plugins fail to install on Bun-only hosts (#160224)

* fix(plugins): install npm-sourced plugins on Bun-only hosts

Bun-only installs have no Node, so every npm-sourced plugin operation that
spawned `npm` failed. OpenClaw's managed plugin roots rely on npm's lockfile,
peer planner, and lock-based rollback, so keep npm's semantics and run a
pinned npm CLI under Bun instead of switching package managers.

- Add npm 11.20.0 as an exact dependency (npm 12.1.0 fails the managed peer
  planner under both Bun and Node).
- One owner, resolveNpmCommand(), serves all plugin install, update,
  uninstall, peer-planning, prune, and npm-config call sites: Node keeps
  `npm` unchanged; Bun runs `<bun> <bundled npm-cli.js>`.
- npm's bundled minimatch/brace-expansion/ip-address sit below the workspace
  security floors and cannot be overridden; a maintainer-approved exception is
  bound to npm@11.20.0's exact bundle, and the npm lock mirror verifies those
  members against the pnpm-locked npm tarball.

* refactor(plugins): keep npm fund suppression out of the shared spawn helper

Keep managed Bun npm installs quiet through their existing --no-fund arguments and safe install environment. Leave the shared process helper unchanged from main to reduce PR #160224 CI fanout.

* fix(plugins): keep the bundled npm lookup error private
This commit is contained in:
Peter Steinberger 2026-09-28 14:01:29 -07:00 • committed by GitHub
parent 21a3a66b50
commit 5c3d2ee897
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
19 changed files with 495 additions and 37 deletions

View file

@ -115,7 +115,7 @@ healthy while leaving the invoking CLI unchanged. The routing and explicit
Bun selection described above apply from the first updater containing the fix;
a newer candidate cannot change the installed updater's first-hop behavior.
Npm-sourced plugins still require npm and Node.
Npm-sourced plugins use OpenClaw's bundled npm 11.20.0 CLI under Bun and do not require a separate Node or npm installation.
## Known limitations
@ -139,6 +139,7 @@ See [Bun](/install/bun) for the workflow and lifecycle trust commands.
| Unreleased (main) | Updates owned split-root Bun Gateway installations in place, retains their runtime pins, and uses explicit Bun executables for package-manager probes and installs. |
| Unreleased (main) | Keeps Bun maintenance children and service runtime selection, and adds `OPENCLAW_PACKAGE_BUN_LAUNCHER` for preinstall validation of Bun-only installs and updater staging. |
| Unreleased (main) | Headless node update checks read the npm registry in-process under Bun instead of running `npm view`; preparing an update still needs npm. #160154 |
| Unreleased (main) | Runs the bundled npm 11.20.0 CLI under Bun for npm-sourced plugin installs, updates, and removal without a separate Node or npm installation. |
| Unreleased (main) | Implicit Gateway and managed node host reinstalls, update refresh, and Doctor's unloaded-service reinstall retain a supported recorded Bun executable without creating a runtime pin. |
| Unreleased (main) | Tool Search code mode (`tool_search_code`) is retired; structured Tool Search needs no Node under Bun. |
| Unreleased (main) | Starts the packaged Chrome DevTools MCP server with the current runtime, so existing-session browser profiles no longer require a Node installation under Bun. |