Skip to content

installer: download only from the release on GitHub for v1.0.2 - #2

Merged
wangqianqianjun merged 2 commits into
mainfrom
installer/github-only
Sep 25, 2026
Merged

wangqianqianjun merged 2 commits into
mainfrom
installer/github-only

Conversation

@wangqianqianjun

Copy link
Copy Markdown
Contributor

Summary

  • install.sh downloads only from https://github.com/FutrixDev/envrelay-skill/releases. ENVRELAY_DOWNLOAD_URL is gone, and with it plain http, file:// and local paths; curl stays held to HTTPS and TLS 1.2.
  • The tests and the release workflow's verify jobs put tests/stubs/curl first on PATH instead. It serves a release packaged on the spot, and refuses any call that is not held to HTTPS and TLS 1.2 or that asks for anything but this repository's release, so the tests run the installer users get.
  • New installer checks: the dry run names the GitHub URL, and a release that lacks an asset fails and installs nothing.
  • Version 1.0.2 in its four places. ADR-027 records the decision and amends ADR-024 and ADR-026. docs/publishing.md says how to read ClawHub's audit verdict, which is separate from moderation.

Why

Only the verify jobs and tests/installer.sh ever set the variable. ClawHub's audit rated v1.0.0 and v1.0.1 Review because of it (A.I.G finding T03, high): it accepted plain http, and SHA256SUMS came from the same place as the files it checks. A variable that only tests use does not belong in what is released.

Compatibility

Anyone who set ENVRELAY_DOWNLOAD_URL to a mirror or a local directory now downloads from GitHub, and a machine that cannot reach GitHub cannot use the installer. The variable shipped only in v1.0.0 and v1.0.1, both released on 2026-09-25. The default path was already GitHub over HTTPS, so nothing else changes for users.

Validation

  • cargo fmt --check, cargo clippy --all-targets --locked -- -D warnings, cargo test --locked (18 passed)
  • SH=<shell> sh tests/installer.sh under sh, dash, bash and zsh: 97 passed, 0 failed under each
  • Mutation checks in a throwaway copy: dropping --proto '=https' --tlsv1.2 from fetch() makes the first scenario fail with "not held to HTTPS", and pointing REPO at another repository makes it fail with "not a download from EnvRelay's release on GitHub"; the unmodified copy passes all 97
  • shellcheck on install.sh, .github/scripts/*.sh, tests/installer.sh and tests/stubs/curl
  • sh .github/scripts/check-versions.sh: versions agree: 1.0.2
  • claude plugin validate --strict .: passed
  • After the merge and before the tag: a trial run of release.yml on main (without a tag it stops after verify), since the verify job changed

🤖 Generated with Claude Code

install.sh no longer reads ENVRELAY_DOWNLOAD_URL. Every download comes
from https://github.com/FutrixDev/envrelay-skill/releases, with curl held
to HTTPS and TLS 1.2, and no http, file:// or local path. Only the release
workflow's verify jobs and tests/installer.sh ever set the variable, and
ClawHub's audit rated v1.0.0 and v1.0.1 Review because of it (T03: it
accepted http, and SHA256SUMS came from the same place as the files).

The tests put tests/stubs/curl first on PATH instead. It serves a release
packaged on the spot and refuses any call that is not held to HTTPS and
TLS 1.2 or that asks for anything but this repository's release, so the
tests run the installer users get. A new scenario covers a missing asset.

Anyone who set ENVRELAY_DOWNLOAD_URL now downloads from GitHub; it shipped
only in v1.0.0 and v1.0.1. ADR-027 records the decision and amends ADR-024
and ADR-026. docs/publishing.md now says how to read ClawHub's audit
verdict, which is separate from moderation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wangqianqianjun

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wangqianqianjun
wangqianqianjun merged commit 37e0a3d into main Sep 25, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant