The Anthropic directory's scan of the release tree raises the warning "Contains a download-and-run command" (RUNTIME_FETCH_EXEC):
- v0.37.0 (
e6cf58f): 2 findings, in pipeline/shell.py and scripts/log.sh.
- v0.38.0 (
e3cfd5b): 3 findings, files not yet seen.
#861 reworded a docstring in pipeline/shell.py and a comment in scripts/log.sh, on the guess that the matcher hit comment text. That guess did not hold: the count went up. v0.38.0 also added #845's SessionStart budget code.
It is a warning, not a hold. The portal says "Where it only appears in documentation, nothing needs to change." Still, it's worth knowing what triggers it, both for us and for claude-supertool and claude-jit-context.
Steps
- In the portal: Versions →
v0.38.0 · e3cfd5b → expand "Contains a download-and-run command". Record the files (and lines, if shown).
- For each: does the plugin really download and run something? If yes, fix it or disclose it. If no, document it as a false positive in
docs/releasing.md, with the exact trigger.
- If a pattern is identifiable, consider teaching
.github/scripts/check_release_tree.py to flag it as a REVIEW line.
[AI-generated]
The Anthropic directory's scan of the
releasetree raises the warning "Contains a download-and-run command" (RUNTIME_FETCH_EXEC):e6cf58f): 2 findings, inpipeline/shell.pyandscripts/log.sh.e3cfd5b): 3 findings, files not yet seen.#861 reworded a docstring in
pipeline/shell.pyand a comment inscripts/log.sh, on the guess that the matcher hit comment text. That guess did not hold: the count went up. v0.38.0 also added #845's SessionStart budget code.It is a warning, not a hold. The portal says "Where it only appears in documentation, nothing needs to change." Still, it's worth knowing what triggers it, both for us and for claude-supertool and claude-jit-context.
Steps
v0.38.0 · e3cfd5b→ expand "Contains a download-and-run command". Record the files (and lines, if shown).docs/releasing.md, with the exact trigger..github/scripts/check_release_tree.pyto flag it as a REVIEW line.[AI-generated]