Skip to content

Directory warning RUNTIME_FETCH_EXEC (download-and-run) rose from 2 to 3 findings on v0.38.0; find the real matches #864

Description

@fdaviddpt

The Anthropic directory's scan of the release tree raises the warning "Contains a download-and-run command" (RUNTIME_FETCH_EXEC):

  • v0.37.0 (e6cf58f): 2 findings, in pipeline/shell.py and scripts/log.sh.
  • v0.38.0 (e3cfd5b): 3 findings, files not yet seen.

#861 reworded a docstring in pipeline/shell.py and a comment in scripts/log.sh, on the guess that the matcher hit comment text. That guess did not hold: the count went up. v0.38.0 also added #845's SessionStart budget code.

It is a warning, not a hold. The portal says "Where it only appears in documentation, nothing needs to change." Still, it's worth knowing what triggers it, both for us and for claude-supertool and claude-jit-context.

Steps

  1. In the portal: Versions → v0.38.0 · e3cfd5b → expand "Contains a download-and-run command". Record the files (and lines, if shown).
  2. For each: does the plugin really download and run something? If yes, fix it or disclose it. If no, document it as a false positive in docs/releasing.md, with the exact trigger.
  3. If a pattern is identifiable, consider teaching .github/scripts/check_release_tree.py to flag it as a REVIEW line.

[AI-generated]

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    lane-otherfits no other lane — kept so an unlabelled issue means untriaged, not 'nothing matched'priority:mediumRecurring cost; compounds if unfixed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions