Files
teamai-cli/docs
Saul Moro facc6104f6 fix: keep self-update off npm link checkouts, and report hook injection only on change (#871) (#874)
* fix(update): leave an npm link checkout alone instead of replacing it with the registry package

When the running CLI is not under node_modules (an npm link checkout),
resolveInstallPrefix returns null and doUpdate ran a prefix-less
npm install -g. That lands in npm's default global prefix, where npm link
put its symlink, so the next hook run swapped the checkout for the
published package. Skip the install and say how to update instead.

* fix(hooks): report OMP, OpenCode and Pi hook injection only when the file changes

These injectors rewrote their file and logged success on every pull, so
an up-to-date pull listed them as injected while Claude and Codex, which
already compare before writing, printed nothing. Use writeIfChanged and
log at debug level when the file is current.

* fix(update): refuse an unsupported install before prompting, and keep the skip in debug.log

Review follow-ups: resolve the install target before the prompt policy so
nobody confirms an update that is then skipped; persist the skip warning
because hooks discard stderr; word it for every null target, not only a
link; tell the user to pull before rebuilding; pass --registry in the
suggested install command.

* fix(hooks): report Hermes and OpenClaw hook injection only when something changes

Both are reached by the pull reconcile and still logged success on every
run. OpenClaw now writes its two files with writeIfChanged; Hermes also
reports whether its config.yaml entry and allowlist were written.

* fix(update): persist the vendored-install skip to debug.log too

Adversarial review follow-up: the Stop hook discards stderr, so the
vendored-layout refusal left no trace while the linked-checkout refusal
next to it is persisted.
2026-09-29 11:06:54 +08:00
..