mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* chore(deps): refresh dependencies with seven-day cutoff Advance eligible application, native, release, and development dependencies published by 2026-09-09T06:51:52Z. Audit new registry resolutions and native artifact hashes, preserving existing security pins and compatibility holds. Adapt MCP Apps 2 tool discovery and host context, retain Clack cancellation handling, and align the updater fixture with its runtime assembly owner. Synchronize native artifact checks, operational docs, and tooling pins. Validation includes frozen installation, full build, CLI rebuild, typechecks, lint, 96 npm package locks, dependency audits, focused runtime and native proofs, and independent review. Exact-head hosted CI is required before land. * fix(deps): preserve scroll ownership and synchronize toolchain contracts * fix(cli): preserve generic wizard option values after Clack update * docs(lobster): clarify credentials for embedded remote calls * test(cli): use Clack cancellation sentinel in prompt fixtures * fix(ios): avoid opening audio input during relay cancellation * test: reuse dependency update fixtures within line limits * fix(crabbox): retain the previous trusted pnpm pin * test(gateway): synchronize task access churn with page selection * test(macos): isolate the challenge timeout transport fixture * fix(macos): preserve hidden windows through deminiaturization * fix(macos): exclude hidden dashboards from window selection
75 lines
2.7 KiB
Bash
Executable file
75 lines
2.7 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
|
|
set -euo pipefail
|
|
|
|
source_root="${1:?trusted Vercel CLI source root is required}"
|
|
destination="${2:?Vercel CLI destination is required}"
|
|
github_output="${3:-}"
|
|
|
|
package_json="${source_root}/package.json"
|
|
package_lock="${source_root}/package-lock.json"
|
|
expected_lock_sha256="a094a59287570aa124a65eb208739a5f4b89b7e8ffe768a3ac38842dd2e2dc85"
|
|
expected_vercel_integrity="sha512-sBxGOvWru8BFdCaqlRhtARTAWDL4FV+Q8APcN63lnOEryTXRce1z3DBWzaakpsts+uF1Sy9MdrTft0zPOWpGuA=="
|
|
test -f "${package_json}"
|
|
test -f "${package_lock}"
|
|
if [[ -e "${destination}" || -L "${destination}" ]]; then
|
|
echo "Vercel CLI destination must not already exist: ${destination}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
install -d -m 0700 "${destination}"
|
|
install -m 0600 "${package_json}" "${destination}/package.json"
|
|
install -m 0600 "${package_lock}" "${destination}/package-lock.json"
|
|
|
|
lock_sha256="$(
|
|
VERCEL_CLI_LOCK="${package_lock}" \
|
|
node -e "const { createHash } = require('node:crypto'); const { readFileSync } = require('node:fs'); process.stdout.write(createHash('sha256').update(readFileSync(process.env.VERCEL_CLI_LOCK)).digest('hex'));"
|
|
)"
|
|
[[ "${lock_sha256}" == "${expected_lock_sha256}" ]] || {
|
|
echo "Pinned Vercel CLI lock SHA-256 mismatch." >&2
|
|
exit 1
|
|
}
|
|
vercel_integrity="$(
|
|
VERCEL_CLI_LOCK="${package_lock}" \
|
|
node -p "require(require('node:path').resolve(process.env.VERCEL_CLI_LOCK)).packages['node_modules/vercel'].integrity"
|
|
)"
|
|
[[ "${vercel_integrity}" == "${expected_vercel_integrity}" ]] || {
|
|
echo "Pinned Vercel CLI integrity mismatch." >&2
|
|
exit 1
|
|
}
|
|
|
|
# Install with lifecycle scripts disabled before any credential is exposed to
|
|
# the CLI process. The committed lock fixes the complete dependency closure.
|
|
(
|
|
cd "${destination}"
|
|
npm ci \
|
|
--ignore-scripts \
|
|
--no-audit \
|
|
--no-fund \
|
|
--omit=dev
|
|
)
|
|
|
|
vercel_version="$(
|
|
VERCEL_CLI_ROOT="${destination}" \
|
|
node -p "require(require('node:path').join(process.env.VERCEL_CLI_ROOT, 'node_modules/vercel/package.json')).version"
|
|
)"
|
|
[[ "${vercel_version}" == "59.13.1" ]] || {
|
|
echo "Pinned Vercel CLI version mismatch: ${vercel_version}" >&2
|
|
exit 1
|
|
}
|
|
test -x "${destination}/node_modules/.bin/vercel"
|
|
vercel_cli="${destination}/node_modules/.bin/vercel"
|
|
# Use Sandbox directly: Vercel's sandbox wrapper overwrites failed remote exits.
|
|
test -x "${destination}/node_modules/.bin/sandbox"
|
|
sandbox_cli="${destination}/node_modules/.bin/sandbox"
|
|
|
|
echo "Materialized vercel@${vercel_version} from lock ${lock_sha256}."
|
|
if [[ -n "${github_output}" ]]; then
|
|
{
|
|
echo "cli=${vercel_cli}"
|
|
echo "sandbox_cli=${sandbox_cli}"
|
|
echo "integrity=${vercel_integrity}"
|
|
echo "lock_sha256=${lock_sha256}"
|
|
echo "version=${vercel_version}"
|
|
} >> "${github_output}"
|
|
fi
|