[audit] fix: bound blink.cmp version range to stay off v2 - #328
stanfish06 wants to merge 1 commit into
Conversation
vim.version.range("1.10.0") is a single-arg open range (>= 1.10.0,
no upper bound), the same anti-pattern already flagged for fff.nvim
in #261 — so the pin doesn't actually block a future blink.cmp v2
install, despite #271 already documenting that v2 is a breaking
config-structure rewrite. Add the explicit upper bound #271
recommended but that was never applied to plugins.lua.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5123337cbf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| -- upper bound keeps this off blink.cmp v2 once it ships: vim.version.range() | ||
| -- with a single arg is an open range (>= 1.10.0, no ceiling), so v2 would | ||
| -- otherwise install silently and break the setup({}) config structure (#271) | ||
| version = vim.version.range(">= 1.10.0, < 2.0.0"), |
There was a problem hiding this comment.
Remove the comma from the version range
vim.version.range() uses npm-style comparator syntax, where comparators in the same set are separated by whitespace rather than commas. Here the comma is parsed as part of 1.10.0,, making the range invalid while package_list is evaluated and preventing the plugin configuration from loading. Use a valid expression such as vim.version.range(">=1.10.0 <2.0.0") (or retain the previous exact pin).
Useful? React with 👍 / 👎.
|
Closing: the premise does not hold. Verified against nvim 0.13.0-dev-1661: A single-arg spec with all three components is an exact pin, not an open range, so the current pin already excludes v2. vim.version.range has no comma-compound parser: it matches the leading >=, M.parse rejects the remainder, and the ceiling is dropped. This change would remove the v2 guard rather than add one. If 1.10.x patch updates are wanted without v2, the correct spec is ^1.10.0 (from 1.10.0, to 2.0.0 exclusive). |
What
plugins.lua:27pinsblink.cmpwithversion = vim.version.range("1.10.0"). A single-arg call tovim.version.range()produces an open range (>= 1.10.0, no ceiling) — the same mismatch between intent and behavior already flagged forfff.nvimin #261. In practice this means the pin does nothing to stop a futureblink.cmpv2 install.Where
lua/config/plugins.lua:27Why it matters
#271 (still open) already documents that
blink.cmpv2 is a complete config-structure rewrite (new source registration model, renamed keymap preset keys, changed completion trigger config) that will break this config'sblink.setup({...})call, and explicitly recommends pinning withvim.version.range(">= 1.0, < 2.0"). That recommendation was never applied — the code still uses the open, single-arg form. So today, the momentblink.cmpv2 tags a release,vim.packwould be free to pull it in and break completion on next sync.Fix
Mechanical, backward-compatible: no change in behavior on the current 1.x line, only adds the ceiling
#271already called for. Also added a short comment explaining why the bound exists, referencing #271.This doesn't close #271 (that issue also covers the eventual v2 migration itself) but does resolve the concrete "the pin isn't actually pinning" gap.
Generated by Claude Code