Skip to content

[audit] vim.version.range("0.9.4") creates an open range ≥0.9.4, not a pin to exactly 0.9.4 #261

Description

@stanfish06

What

plugins.lua:10 marks fff.nvim with:

version = vim.version.range("0.9.4"),

The comment on the same line says "this package breaks frequently, specify version", implying the intent is to pin fff.nvim at exactly 0.9.4. But vim.version.range("0.9.4") produces a range constraint meaning >= 0.9.4 with no upper bound — any later release also satisfies it.

Where

lua/config/plugins.lua:10

Why it matters

If vim.pack enforces version ranges during updates (behaviour may vary by nightly build), fff.nvim could be updated to a breaking release while the user believes it is pinned. The comment intent and the actual constraint are mismatched.

Recommended action

To constrain to the 0.9.x line only, use an explicit upper bound:

version = vim.version.range(">= 0.9.4, < 0.10"),

To pin to a single exact release, use a git SHA instead of a version range (vim.pack accepts a pin / commit-hash field depending on nightly API). Alternatively, accept that the constraint is a lower-bound floor and update the comment to reflect that.

Also worth verifying: whether vim.pack.add() actually reads and enforces the version field at all, since it is a nightly/experimental API. If it is ignored, the lazy = true field on the same entry may also be silently ignored (fff.nvim would then load at startup rather than on demand).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions