Conversation
Launch the CLI through a native process instead of evaluating executable and CLI paths as PowerShell source, and reject project-level prefix settings so repository config cannot redirect CLI selection. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
martinrrm
marked this pull request as ready for review
October 1, 2026 18:18
martinrrm
marked this pull request as draft
October 1, 2026 18:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Invoke-Expressioninbin/npm.ps1andbin/npx.ps1with a native process launch usingSystem.Diagnostics.ProcessStartInfoandUseShellExecute = false. The selected Node executable and CLI path no longer become PowerShell source.-Filebranches unchanged.prefixbefore loading project configuration. Previously, the configuration loader logged that this setting was prohibited but still made it effective.$()and single quotes, plus assertions that the wrappers do not useInvoke-Expression. Extend the config regression to verify that the project prefix is absent and cannot change the effective global prefix.Refs github/npm#15799, finding CLI-CROW-CMD-002.
Why both changes are needed
Quoting a path inside an
Invoke-Expressionstring does not prevent PowerShell subexpression evaluation. Removing that evaluation boundary addresses the wrapper sink.Rejecting project
prefixindependently prevents a repository's.npmrcfrom redirecting CLI selection to repository-controlled JavaScript. This is not a substitute for removing the wrapper sink.Validation
git diff --check.@npmcli/configTAP tests are blocked locally:tapis unavailable.eslintis unavailable.@npmcli/template-ossis also unavailable.Before marking ready
release/v11andrelease/v10.Draft intentionally: the implementation and regressions are available for discussion, but runtime verification is still outstanding.