Skip to content

[audit] fix: bound blink.cmp version range to stay off v2 - #328

Closed
stanfish06 wants to merge 1 commit into
masterfrom
audit/blink-cmp-version-range
Closed

stanfish06 wants to merge 1 commit into
masterfrom
audit/blink-cmp-version-range

Conversation

@stanfish06

Copy link
Copy Markdown
Owner

What

plugins.lua:27 pins blink.cmp with version = vim.version.range("1.10.0"). A single-arg call to vim.version.range() produces an open range (>= 1.10.0, no ceiling) — the same mismatch between intent and behavior already flagged for fff.nvim in #261. In practice this means the pin does nothing to stop a future blink.cmp v2 install.

Where

lua/config/plugins.lua:27

Why it matters

#271 (still open) already documents that blink.cmp v2 is a complete config-structure rewrite (new source registration model, renamed keymap preset keys, changed completion trigger config) that will break this config's blink.setup({...}) call, and explicitly recommends pinning with vim.version.range(">= 1.0, < 2.0"). That recommendation was never applied — the code still uses the open, single-arg form. So today, the moment blink.cmp v2 tags a release, vim.pack would be free to pull it in and break completion on next sync.

Fix

version = vim.version.range(">= 1.10.0, < 2.0.0"),

Mechanical, backward-compatible: no change in behavior on the current 1.x line, only adds the ceiling #271 already called for. Also added a short comment explaining why the bound exists, referencing #271.

This doesn't close #271 (that issue also covers the eventual v2 migration itself) but does resolve the concrete "the pin isn't actually pinning" gap.


Generated by Claude Code

vim.version.range("1.10.0") is a single-arg open range (>= 1.10.0,
no upper bound), the same anti-pattern already flagged for fff.nvim
in #261 — so the pin doesn't actually block a future blink.cmp v2
install, despite #271 already documenting that v2 is a breaking
config-structure rewrite. Add the explicit upper bound #271
recommended but that was never applied to plugins.lua.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5123337cbf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread lua/config/plugins.lua
-- upper bound keeps this off blink.cmp v2 once it ships: vim.version.range()
-- with a single arg is an open range (>= 1.10.0, no ceiling), so v2 would
-- otherwise install silently and break the setup({}) config structure (#271)
version = vim.version.range(">= 1.10.0, < 2.0.0"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove the comma from the version range

vim.version.range() uses npm-style comparator syntax, where comparators in the same set are separated by whitespace rather than commas. Here the comma is parsed as part of 1.10.0,, making the range invalid while package_list is evaluated and preventing the plugin configuration from loading. Use a valid expression such as vim.version.range(">=1.10.0 <2.0.0") (or retain the previous exact pin).

Useful? React with 👍 / 👎.

@stanfish06

Copy link
Copy Markdown
Owner Author

Closing: the premise does not hold. Verified against nvim 0.13.0-dev-1661:

vim.version.range("1.10.0")              from=1.10.0 to=1.10.0   has("2.0.0") = false
vim.version.range(">= 1.10.0, < 2.0.0")  from=1.10.0 to=nil      has("2.0.0") = true

A single-arg spec with all three components is an exact pin, not an open range, so the current pin already excludes v2. vim.version.range has no comma-compound parser: it matches the leading >=, M.parse rejects the remainder, and the ceiling is dropped. This change would remove the v2 guard rather than add one.

If 1.10.x patch updates are wanted without v2, the correct spec is ^1.10.0 (from 1.10.0, to 2.0.0 exclusive).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deps] fff.nvim at 0.9.6 (config targets 0.9.4); blink.cmp v2 imminent with breaking config changes

2 participants