The documented npm --prefix plugins/codex-co-engineer run setup command can pass its local npm_config_prefix into setup's child npm install --global. On the 3.4.3 release installation, this created dependencies under the plugin's lib/node_modules and three generated executable links in its bin directory. Registering that local marketplace then copied the unintended dependencies into the plugin cache. The 476 released plugin files were unchanged, but the installation no longer had the exact release inventory.
bin/setup.mjs already removes npm_config_prefix and npm_config_local_prefix when inspecting the global npm root. Its installation subprocess should consistently use the intended global prefix. Preserve intentionally configured global-prefix behavior; do not clear unrelated user environment or modify existing credentials/configuration.
The current workaround is to invoke the released script directly from the release checkout, outside an npm --prefix invocation:
node plugins/codex-co-engineer/bin/setup.mjs
node plugins/codex-co-engineer/bin/setup.mjs --check
The source-archive integrity check passed; this is an installation-path defect, not a changed published artifact. The first failed inventory and local recovery evidence are retained privately. The release notes disclose the workaround. Clean-environment onboarding remains unqualified.
Acceptance for a follow-up patch:
- The documented setup command installs its pinned dependencies into the intended global prefix without adding
lib/node_modules or generated bin links to the plugin source.
- Exercise prefix inheritance with a fake npm process in an isolated fixture; do not install real global packages in the regression test.
- Existing explicit global-root/prefix configuration and the check path agree.
- The shipped plugin file inventory remains unchanged by setup and normal plugin registration.
- Update source and packaged setup guidance together; independently review the fix and qualify the changed release candidate.
The documented
npm --prefix plugins/codex-co-engineer run setupcommand can pass its localnpm_config_prefixinto setup's childnpm install --global. On the 3.4.3 release installation, this created dependencies under the plugin'slib/node_modulesand three generated executable links in itsbindirectory. Registering that local marketplace then copied the unintended dependencies into the plugin cache. The 476 released plugin files were unchanged, but the installation no longer had the exact release inventory.bin/setup.mjsalready removesnpm_config_prefixandnpm_config_local_prefixwhen inspecting the global npm root. Its installation subprocess should consistently use the intended global prefix. Preserve intentionally configured global-prefix behavior; do not clear unrelated user environment or modify existing credentials/configuration.The current workaround is to invoke the released script directly from the release checkout, outside an npm
--prefixinvocation:The source-archive integrity check passed; this is an installation-path defect, not a changed published artifact. The first failed inventory and local recovery evidence are retained privately. The release notes disclose the workaround. Clean-environment onboarding remains unqualified.
Acceptance for a follow-up patch:
lib/node_modulesor generated bin links to the plugin source.