Skip to content

Add user-configurable preferences for handling self-updating modules #1403

Description

@coreybutler

It is possible to manually revalidate global modules that self-update using nvm reshim, but this is not an ideal workflow. It is possible to auto-validate self-updating modules, but this can be exploited by compromised packages.

There should be a policy allowing or disabling auto-revalidation, as well as an allow/block-list to configure automatic revalidation of trusted global modules.

It also happens with some commands that can update themselves.

$ nvm --version
v2.0.1-hotfix.1
$ npm i -g opencode-ai@1.18.30
$ opencode upgrade
$ opencode
NVM blocked package-manager execution because a delegated command could not be trusted.

Command: opencode
File: ~\AppData\Local\Author Software\nvm\installs\v26.8.1\opencode.cmd
Reason: delegated script changed since it was trusted
Action: Run `nvm reshim` (re-signs package-manager scripts) or `nvm doctor --autofix`.
If this change was unexpected, contact your administrator and review NVM event logs.
Event code: NVM4306

and nvm reshim resolves the issue. Blocking a self-updatable program after updating may be a good idea, but it would be good if we could whitelist some executables.

Originally posted by @ziyuang in #1379

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions