Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
b2ee6da
feat(config): add global versionChecks.enabled toggle
YauheniHHH Sep 22, 2026
4f618f7
refactor(utils): share extractVersion across callers
YauheniHHH Sep 22, 2026
2978b52
feat(utils): add 24h TTL npm-lookup cache
YauheniHHH Sep 22, 2026
459963d
feat(agents): add resolveSupportedVersion live-tracking accessor
YauheniHHH Sep 22, 2026
1cfbfb0
feat(agents): resolve supportedVersion live in BaseAgentAdapter
YauheniHHH Sep 22, 2026
38bcbbc
feat(agents): resolve --supported install version live for claude
YauheniHHH Sep 22, 2026
2fea09d
feat(kimi): resolve --supported install version live
YauheniHHH Sep 22, 2026
40e16ef
feat(cli): unify version checks across all allowlisted agents
YauheniHHH Sep 22, 2026
c11c7eb
fix(cli): reword Claude version copy to newer-version framing
YauheniHHH Sep 22, 2026
b5d21c4
feat(cli): add --refresh-versions to bypass the version cache
YauheniHHH Sep 22, 2026
b3820dc
fix(agents): address code review findings for live version tracking
YauheniHHH Sep 23, 2026
3d693d3
docs(agents): add SDLC planning artifacts for EPMCDME-14767
YauheniHHH Sep 23, 2026
2fa2f8f
fix(utils): quote the base command in exec()'s shell mode, not just args
YauheniHHH Sep 24, 2026
6e36ebd
fix(agents): correct "recommends"/"tested" wording to reflect live tr…
YauheniHHH Sep 24, 2026
133fcf7
fix(agents): fix Windows version checks and suppress agent self-updaters
YauheniHHH Sep 24, 2026
b611dc2
fix(agents): mock resolveSupportedVersion in Codex version-support tests
YauheniHHH Sep 28, 2026
53c536a
docs(agents): explain the resolveSupportedVersion mock in Codex versi…
YauheniHHH Sep 28, 2026
f300a9a
fix(utils): pass raw shell command lines through exec() unquoted
YauheniHHH Sep 28, 2026
a15f8e6
fix(utils): never serve an expired version cache entry as current
YauheniHHH Sep 28, 2026
62937ef
fix(agents): treat an unknown tracked version as unconfigured
YauheniHHH Sep 28, 2026
6ae10af
docs(config): document the agent version-check toggle and revise spec
YauheniHHH Sep 28, 2026
4e7419d
fix(cli): refresh doctor versions per package instead of wiping the c…
YauheniHHH Sep 28, 2026
20a87d9
fix(agents): parse Codex config.toml before adding the update-check key
YauheniHHH Sep 28, 2026
5687b80
test(cli): cover the update stale-fallback gate and --force-refresh
YauheniHHH Sep 28, 2026
b3a22e2
docs(config): note self-updater settings persist; settle tracking copy
YauheniHHH Sep 28, 2026
ceb4c58
refactor(agents): document version-resolution exports, use named fs i…
YauheniHHH Sep 28, 2026
3c2f4d9
test(agents): make the live tracked version differ from the fallback
YauheniHHH Sep 28, 2026
5e22e16
fix(utils): read latest agent versions from the npm registry directly
YauheniHHH Sep 28, 2026
232b37f
fix(agents): track only the ticket's agents; keep others' pinned version
YauheniHHH Sep 28, 2026
b9ca71b
refactor(cli): drop version refresh flags; ask before --supported rei…
YauheniHHH Sep 28, 2026
815b824
docs(config): describe registry lookup; keep only spec and plan
YauheniHHH Sep 28, 2026
946a18e
fix(cli): check the registry fresh on codemie update
YauheniHHH Sep 29, 2026
a9b8ced
refactor(agents): stop asking to bump live-tracked version constants
YauheniHHH Sep 29, 2026
8ade0cc
docs(agents): mark the Claude version spec as partly superseded
YauheniHHH Sep 29, 2026
0929a37
refactor(agents): leave Codex and Gemini self-updaters alone
YauheniHHH Sep 29, 2026
cffd2ba
style(agents): restore original spacing in version notices
YauheniHHH Sep 29, 2026
c86c8e3
test(agents): drop a duplicate install-version fallback test
YauheniHHH Sep 29, 2026
ff601c5
fix(utils): never expand env vars from a project .npmrc
YauheniHHH Sep 29, 2026
d4dec34
fix(agents): don't advise a downgrade when ahead of the tracked version
YauheniHHH Sep 29, 2026
c1252e4
fix(cli): report agents whose update lookup failed
YauheniHHH Sep 29, 2026
736a150
fix(utils): skip version lookups for 10 minutes after a failure
YauheniHHH Sep 29, 2026
f3e272a
fix(agents): run Kimi and Claude --version through a shell on Windows
YauheniHHH Sep 29, 2026
b7922bf
fix(utils): resolve the registry lookup proxy via the shared system p…
YauheniHHH Oct 5, 2026
ebe9758
test(tests): check the agent-suite Claude install against the tracked…
YauheniHHH Oct 5, 2026
7900da1
test(utils): isolate npm-registry tests from the system proxy
YauheniHHH Oct 5, 2026
3d1581c
fix(utils): read registry and proxy settings from user npm config only
YauheniHHH Oct 6, 2026
26a604f
fix(utils): keep repo-chosen npm settings out of the shared version c…
YauheniHHH Oct 7, 2026
2e90613
fix(agents): harden live version checks against failures and lagging …
YauheniHHH Oct 7, 2026
23f49f9
fix(utils): keep registry URLs and credentials out of the version cac…
YauheniHHH Oct 7, 2026
501712d
fix(agents): keep launching when the minimum-version check fails
YauheniHHH Oct 7, 2026
1bef8f3
fix(agents): install the minimum when the registry latest is below it
YauheniHHH Oct 7, 2026
0650714
test(utils): cover the user .npmrc https-proxy for https registries
YauheniHHH Oct 7, 2026
27cfc4f
fix(agents): stop installs of the tracked version when the registry l…
YauheniHHH Oct 7, 2026
09c3e9c
fix(cli): warn about a below-minimum Claude during setup
YauheniHHH Oct 7, 2026
9d1abd7
fix(utils): fail the version lookup when the configured npm proxy is …
YauheniHHH Oct 7, 2026
bd2b762
docs(agents): add SDLC artifacts for the PR 576 review-fix run
YauheniHHH Oct 7, 2026
76847b0
fix(cli): keep plain install of an installed agent a no-op below the …
YauheniHHH Oct 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions docs/CONFIGURATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,28 @@ be used as the permanent corporate configuration.
- Cache location: `~/.codemie/.last-update-check`
- See `codemie self-update --help` for manual update options

#### Agent Version Checks

| Variable | Description | Default | Example |
|----------|-------------|---------|---------|
| `CODEMIE_VERSION_CHECKS_ENABLED` | Compare installed agents (Claude, Codex, Gemini, Kimi) against their latest release on npm | `true` | `false` to turn checks off |

When enabled, CodeMie reads each agent's latest release from your configured npm registry (cached for 24h) and shows a one-time notice when your installed version differs; `codemie doctor` uses the same value, and `codemie update` always fetches it fresh. The lookup is a single HTTPS request that honors npm's `registry`/`@scope:registry` settings and npm's `https-proxy`/`proxy`/`noproxy` settings; without an npm proxy it uses `HTTPS_PROXY`/`HTTP_PROXY`/`NO_PROXY` and then the Windows system proxy or PAC (see [Windows system proxy and PAC](#windows-system-proxy-and-pac)). Registries that require authentication aren't supported. npm's `cafile`/`ca`/`strict-ssl` settings aren't read: behind a TLS-intercepting proxy, trust the corporate CA with `NODE_EXTRA_CA_CERTS`, or set `CODEMIE_VERSION_CHECKS_ENABLED=false`. A failed lookup is written to the CodeMie log file and never stops a launch — the check is simply skipped. While the registry is unreachable, a launch can wait up to 3 seconds for the lookup; after a failure CodeMie skips further lookups for 10 minutes (`codemie update` always retries). Set `CODEMIE_VERSION_CHECKS_ENABLED=false` if you work offline. These npm settings come from your user `.npmrc` (or `npm_config_*` environment variables) only; a project's `.npmrc` is ignored for this lookup, so a checked-out repository can't choose the registry or proxy that decides the tracked version. When CodeMie is started through `npm run` or `npx`, npm exports the project's settings as `npm_config_*` variables, so those are ignored too and only `~/.npmrc` is read.

With checks off there is no lookup, notice, or update offer for these agents. `codemie install <agent> --supported` then installs the latest release, and the minimum-version guard (which refuses versions known to be broken) still applies.

The same switch can be set in `~/.codemie/codemie-cli.config.json` (all projects) or a project's `.codemie/codemie-cli.config.json`:

```json
{
"workspace": {
"versionChecks": { "enabled": false }
}
}
```

Precedence: the env var, then the project setting, then the global one. Only an explicit `false` turns checks off.

#### Security & File Access

| Variable | Description | Example |
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# Claude Code CLI Installation and Version Management

> **Superseded in part (EPMCDME-14767).** The hand-maintained "supported version" described below
> is no longer the source of truth. Claude, Codex, Gemini and Kimi now track their latest npm
> release live (cached for 24h), behind the global `versionChecks.enabled` toggle. The metadata
> `supportedVersion` only marks an agent as version-checked and is never shown as current: when the
> lookup fails or checks are off, the tracked version is unknown and `install --supported` installs
> the latest release. `minimumSupportedVersion` stays hand-maintained and still blocks launch. See
> "Agent Version Checks" in `docs/CONFIGURATION.md`. The installation flow below is unchanged.

## Specification Summary

**Last Updated**: 2026-01-29
Expand Down
384 changes: 384 additions & 0 deletions docs/superpowers/tasks/2026-09-22-agents-live-version-check/plan.md

Large diffs are not rendered by default.

228 changes: 228 additions & 0 deletions docs/superpowers/tasks/2026-09-22-agents-live-version-check/spec.md

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
{
"schema": 1,
"generated": "2026-10-07T00:00:00Z",
"dimensions": {
"component_scope": { "score": 4, "label": "L" },
"requirements_clarity": { "score": 2, "label": "S" },
"technical_risk": { "score": 4, "label": "L" },
"file_change_estimate": { "score": 6, "label": "XXL" },
"dependencies": { "score": 1, "label": "XS" },
"affected_layers": { "score": 3, "label": "M" }
},
"total": 20,
"size": "M",
"band_range": "15-20",
"files_changed": 18,
"routing": "brainstorming",
"key_reasoning": [
{
"dimension": "component_scope",
"reason": "Targeted fixes across about 6 existing components in 3 layers: the version-cache and npm-registry shared utilities, version-resolution plus BaseAgentAdapter and types in the agent core, and the install and setup CLI commands. No new abstractions; the work extends the existing live-version-tracking design from PR #576. Base M, bumped to L because it touches core shared utilities (version-cache, npm-registry) that every live-tracked agent and command uses."
},
{
"dimension": "technical_risk",
"reason": "The changes are security-sensitive. The cache key no longer embeds the registry URL (which can carry credentials): it uses the URL origin plus a SHA-256 hash, and legacy raw-URL keys are dropped when the cache loads, so the next save removes them from disk. When a configured npm proxy is invalid, the lookup now fails instead of quietly going direct, and the proxy value is never logged. The closest existing pattern (sanitizeLogArgs-style log scrubbing) does not cover secrets stored in persisted cache keys or the no-direct-fallback rule, so Technical Risk was bumped from M to L. The rest (guarded minimum comparison, AgentInstallationError when the registry latest is below the minimum, setup warning) follows established patterns and is easy to roll back."
},
{
"dimension": "file_change_estimate",
"reason": "The diffstat reports 18 files changed (472 insertions, 28 deletions), which maps to XXL (16+) on the actual-mode scale. The count is inflated by tests and docs: 9 test files, 2 docs files (CONFIGURATION.md and the PR #576 spec) and 7 source files across src/utils, src/agents/core and src/cli/commands. The source footprint alone would score about L."
},
{
"dimension": "requirements_clarity",
"reason": "The work comes from specific, itemized code-review findings (round 4 and 5) on an existing PR, each with a clear expected behavior. No open design decisions."
}
],
"red_flags_applied": [
"Technical Risk bumped from M to L: security requirement. Registry credentials must never reach the persisted version-cache keys, and a configured npm proxy must not be silently bypassed. The existing log-sanitization pattern does not cover either case.",
"Component Scope bumped from M to L: touches core shared utilities (src/utils/version-cache.ts, src/utils/npm-registry.ts) used by every live-tracked agent, install, setup and update."
],
"split_recommendation": null
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Code review — 2026-10-07-pr576-review-round4-fixes (2026-10-07)

**request-changes** · confidence: high · 8 blocking · 2 deferred · 16 filtered as noise
Coverage: blind ✓ · edge-case ✓ · verification-gap ✓ · acceptance ✓ (4/4 lenses ran)

## Look here first

- `src/cli/commands/install.ts:180` — [other: backwards compatibility] `--supported` on a lagging mirror prompts "Reinstall with the latest release?" but installs the minimum, which can downgrade the agent — CR-003
- `src/cli/commands/install.ts:130` — [other: lagging mirror] plain `install claude/codex` installs the below-minimum `latest` that the launch gate then refuses — CR-002
- `src/cli/commands/setup.ts:787` — [other: version gate] setup shows a green "installed" line for a Claude version below the minimum — CR-005
- `src/utils/npm-registry.ts:117` — [security] an invalid npm proxy setting silently sends the lookup direct, bypassing the configured proxy — CR-007
- `docs/superpowers/tasks/2026-09-22-agents-live-version-check/spec.md` — [other: spec] spec §2 does not describe the install-the-minimum path — CR-001

## Also flagged

- `src/utils/npm-registry.ts` — [infra] the user's .npmrc `cafile`/`ca`/`strict-ssl` settings are ignored, so lookups fail behind TLS-intercepting proxies — CR-008
- `src/cli/commands/install.ts:213` — [other: copy] `install opencode|pi --supported` blames disabled checks or npm, and no test covers it — CR-004
- `src/cli/commands/update.ts:63` — [other: tests] no test for a failed built-in agent lookup now reported as LOOKUP_FAILED — CR-006

## Checked and clean

commit-format ✓ · code-quality ✓ · security ✓ · 2 deferred → code-review-deferred.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Deferred from code review — 2026-10-07-pr576-review-round4-fixes (2026-10-07)

- **checkAndInstallClaude has no test** — `src/cli/commands/setup.ts:787` — The first-run setup branch for an installed Claude changed its isNewer output and its timeout, and no test reaches checkAndInstallClaude. Pre-existing: the original task explicitly excludes adding a checkAndInstallClaude test from this round.
- **Kimi update routed through npm** — `src/cli/commands/update.ts` — updateAgent special-cases only Claude for the native installer, so a live-tracked Kimi update falls through to npm installGlobal. Pre-existing: the original task names "Kimi update via npm" as a pre-existing item deferred last round.
Loading