Skip to content

fix: catch outdated version pins via package-manager CLI - #69

Merged
algomaster99 merged 3 commits into
mainfrom
fix/bash-pkg-manager-bypass
Sep 26, 2026
Merged

algomaster99 merged 3 commits into
mainfrom
fix/bash-pkg-manager-bypass

Conversation

@algomaster99

@algomaster99 algomaster99 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary

The Bash branch of runHook only caught manifest bypasses that looked like a direct file rewrite (looksLikeManifestWrite: redirects, tee, sed -i, cp/mv, ...). It didn't recognize a package manager's own CLI syntax for pinning an exact version, which writes the manifest just as directly:

  • go get module@v1.2.3
  • npm install/add/i pkg@1.2.3 (also pnpm/yarn)
  • pip/pip3/poetry/uv install/add pkg==1.2.3
  • cargo add crate@1.2.3

These commands exited 0 with no outdated-dependency check at all, so Claude could pin a stale version through the CLI and never see it flagged - found while investigating a benchmark rep (go-top-03-go-spew, hook condition) where go get github.com/davecgh/go-spew@v1.1.0 slipped through despite the hook being active.

A bare install/get with no version, or one pinned to a range (pkg@^1.2.3, pkg@latest, pip install pkg>=1.0), is left alone - there's nothing outdated to flag yet, or nothing exact for a resolver to check.

parsePkgManagerPin extracts the ecosystem/name/version out of a matched command, and checkPkgManagerPin resolves that package's actual latest release the same way the Write/Edit path does - reusing pins.Diff - and only blocks when the pin is genuinely outdated, reporting the correct version in the same name current -> latest format Write/Edit already uses. A pin that's already at latest passes through untouched rather than always being redirected to Write/Edit.

Before / after

$ echo '{"tool_name":"Bash","tool_input":{"command":"go get github.com/davecgh/go-spew@v1.1.0"}}' | ./yul
# before: exit 0, silent
# after:
outdated dependency pinned via package manager CLI, use this version instead:
  github.com/davecgh/go-spew  v1.1.0 -> v1.1.1
$ echo $?
2

$ echo '{"tool_name":"Bash","tool_input":{"command":"go get github.com/davecgh/go-spew@v1.1.1"}}' | ./yul
# already latest: exit 0, silent, same as before
$ echo $?
0

🤖 Generated with Claude Code

…version

Bash writes to a manifest via a redirect/tee/sed-i/etc were already caught by
looksLikeManifestWrite, but a package manager's own CLI syntax for pinning an
exact version (go get mod@v1.2.3, npm install pkg@1.2.3, pip install
pkg==1.2.3, cargo add crate@1.2.3, ...) wrote the manifest just as directly
and slipped straight past the hook, exit 0, with no outdated-dependency check
at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Comment thread main.go Outdated
…nager pins

Per review feedback on #69: rather than always blocking a package-manager
CLI pin (go get/npm install/pip install/cargo add ...@Version) outright,
resolve its actual latest release the same way the Write/Edit path does
(reusing pins.Diff) and only block when the pinned version is genuinely
outdated, reporting the correct version the same way. An already-latest
CLI pin now passes through untouched instead of always being redirected to
Write/Edit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Comment thread main.go Outdated
@algomaster99 algomaster99 changed the title fix: block package-manager CLI commands that pin an exact dependency version fix: catch outdated version pins via package-manager CLI Sep 26, 2026
@algomaster99
algomaster99 merged commit bef11f3 into main Sep 26, 2026
2 checks passed
@algomaster99
algomaster99 deleted the fix/bash-pkg-manager-bypass branch September 26, 2026 18:08
frankreyesgarcia added a commit to frankreyesgarcia/yul that referenced this pull request Sep 27, 2026
…hains-project#65, package-manager CLI pin detection chains-project#69, ecosyste.ms GH Actions SHA resolution chains-project#64, and more)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant