(feat): adding update command - #9
Merged
Merged
Conversation
…ksum parsing - Switch getLatestVersion to GitHub REST API JSON response instead of redirect parsing - Replace identity maps in getBinaryAssetName with Set-based validation - Parse checksum line once and reuse; compute Buffer.from(binary) once
ky sends the runtime's default User-Agent automatically; GitHub only rejects requests with an empty header, not a missing one.
Single-use method with no reuse benefit; inlining reduces indirection.
Fetch checksums before the binary to validate platform support dynamically instead of hardcoding allowed platforms/archs.
Both npm and binary paths now run automatically. Removes the manual_update_required status — all updates return status: updated.
lifeofpavs
marked this pull request as ready for review
March 20, 2026 17:33
Ship install.sh as a GitHub release asset and fetch it from the release URL instead of raw.githubusercontent.com, so the update command uses the same versioned script that users install with.
|
|
||
| try { | ||
| const script = await ky.get(scriptUrl).text(); | ||
| await writeFile(scriptPath, script); |
Check failure
Code scanning / CodeQL
Insecure temporary file High
Collaborator
Author
There was a problem hiding this comment.
Addressed in a follow-up. The updater now creates a unique temp directory with mkdtemp(...), writes install.sh inside that directory with mode 0o700, and removes the directory in finally, so the predictable temp-file path is gone.
Avoid predictable temp file path by creating a unique directory with mkdtemp, preventing symlink attacks flagged by GitHub code scanning.
The script is already in the repo — import it as text so Bun bundles it into the compiled binary. Removes the runtime network fetch.
Revert the text import approach — fetching from the release URL is cleaner than importing a shell script as a TS text module.
Remove install method detection, package manager commands, and binary update logic. The update command now fetches and runs install.sh which handles volta/npm/binary fallback internally.
macOS 15+ ships a native /sbin/sha256sum, so the shasum -a 256 fallback for older versions is unnecessary.
AaronCQL
approved these changes
Mar 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
jup update— a self-update command that fetches and runsinstall.shfrom the matching release tag, which handles volta/npm/binary detection and installation internally.Update command
jup update— fetchesinstall.shfrom the release tag URL, writes it to a secure temp directory (mkdtemp), and executes itjup update --check— reports whether an update is available without installing/repos/jup-ag/cli/releases/latest)install.sh hardening
1. Secure temp file creation
The original script wrote to a predictable path (
/tmp/jup), which is vulnerable to symlink attacks — an attacker could place a symlink at/tmp/juppointing to another file, and the script would overwrite it. The fix usesmktemp -dfor a unique temp directory andtrapfor cleanup:2. Checksum grep error handling
Under
set -e, ifgrepfinds no matching checksum line it returns exit code 1, killing the script with no useful message. The fix suppresses the exit and provides an actionable error: