installer: download only from the release on GitHub for v1.0.2 - #2
Merged
Merged
Conversation
install.sh no longer reads ENVRELAY_DOWNLOAD_URL. Every download comes from https://github.com/FutrixDev/envrelay-skill/releases, with curl held to HTTPS and TLS 1.2, and no http, file:// or local path. Only the release workflow's verify jobs and tests/installer.sh ever set the variable, and ClawHub's audit rated v1.0.0 and v1.0.1 Review because of it (T03: it accepted http, and SHA256SUMS came from the same place as the files). The tests put tests/stubs/curl first on PATH instead. It serves a release packaged on the spot and refuses any call that is not held to HTTPS and TLS 1.2 or that asks for anything but this repository's release, so the tests run the installer users get. A new scenario covers a missing asset. Anyone who set ENVRELAY_DOWNLOAD_URL now downloads from GitHub; it shipped only in v1.0.0 and v1.0.1. ADR-027 records the decision and amends ADR-024 and ADR-026. docs/publishing.md now says how to read ClawHub's audit verdict, which is separate from moderation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
1 similar comment
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
install.shdownloads only fromhttps://github.com/FutrixDev/envrelay-skill/releases.ENVRELAY_DOWNLOAD_URLis gone, and with it plain http,file://and local paths; curl stays held to HTTPS and TLS 1.2.tests/stubs/curlfirst onPATHinstead. It serves a release packaged on the spot, and refuses any call that is not held to HTTPS and TLS 1.2 or that asks for anything but this repository's release, so the tests run the installer users get.docs/publishing.mdsays how to read ClawHub's audit verdict, which is separate from moderation.Why
Only the verify jobs and
tests/installer.shever set the variable. ClawHub's audit rated v1.0.0 and v1.0.1 Review because of it (A.I.G finding T03, high): it accepted plain http, andSHA256SUMScame from the same place as the files it checks. A variable that only tests use does not belong in what is released.Compatibility
Anyone who set
ENVRELAY_DOWNLOAD_URLto a mirror or a local directory now downloads from GitHub, and a machine that cannot reach GitHub cannot use the installer. The variable shipped only in v1.0.0 and v1.0.1, both released on 2026-09-25. The default path was already GitHub over HTTPS, so nothing else changes for users.Validation
cargo fmt --check,cargo clippy --all-targets --locked -- -D warnings,cargo test --locked(18 passed)SH=<shell> sh tests/installer.shunder sh, dash, bash and zsh: 97 passed, 0 failed under each--proto '=https' --tlsv1.2fromfetch()makes the first scenario fail with "not held to HTTPS", and pointingREPOat another repository makes it fail with "not a download from EnvRelay's release on GitHub"; the unmodified copy passes all 97shellcheckoninstall.sh,.github/scripts/*.sh,tests/installer.shandtests/stubs/curlsh .github/scripts/check-versions.sh: versions agree: 1.0.2claude plugin validate --strict .: passedrelease.ymlon main (without a tag it stops after verify), since the verify job changed🤖 Generated with Claude Code