T08 · Insecure Dependencies
- Location
scripts/upgrade-openclaw.sh:203- Finding
Unconfirmed and Unpinned Global Package Installation
- Content
View full analysis
/dev/null || echo "unknown") if [ "$TARGET_VERSION" = "unknown" ]; then TARGET_VERSION=$($NPM_BIN view openclaw version --registry https://registry.npmjs.org 2>/dev/null || echo "unknown") fi log "目标版本: v$TARGET_VERSION" if [ "$TARGET_VERSION" = "unknown" ]; then log "无法获取目标版本号,继续升级" elif [ "$TARGET_VERSION" = "$INSTALLED_VERSION" ]; then log "当前已是最新版 (v$INSTALLED_VERSION)" ok "无需升级,退出" exit 0 else RN=$(curl -sL --connect-timeout 10 \ "https://api.github.com/repos/openclaw/openclaw/releases/tags/v${TARGET_VERSION}" 2>/dev/null \ | python3 -c " import sys, json try: d = json.load(sys.stdin) body = d.get('body', '') name = d.get('name', '') html = d.get('html_url', '') lines = body.strip().split('\n') safe = [l for l in lines[:50] if l.strip()] print(f'--- {name} ---') for l in safe: print(l) if len(lines) > 50: print('...') print(f'--- Full: {html} ---') except: print('ParseError') " 2>/dev/null || echo "API 请求失败") log "=== Release Notes ===" echo "$RN" | while IFS= read -r l; do log "$l"; done log "=== End ===" BREAKING_HINT=$(echo "$RN" | grep -ci "breaking\|BREAKING\|重新.*密码\|密码.*变更\|credential\|re-auth\|reauthenticate\|password.*change\|migration" || true) if [ "$BREAKING_HINT" -gt 0 ]; then log "⚠️ 含疑似 breaking change 关键词,升级后留意" fi fi # ──────────────────────────────────────────────────────────────────────── step "阶段 3: 旁路备份" # ──────────────────────────────────────────────────────────────────────── BAKDIR="${RUN_DIR}-fallback" rm -rf "$BAKDIR" log "备份 $RUN_DIR → $BAKDIR ..." cp -r "$RUN_DIR" "$BAKDIR ...[truncated 4487 chars]- Remediation
View remediation
` and verify that it matches the resolved version. 2. **Pin the exact package version** - Validate `TARGET_VERSION` against a strict SemVer pattern. - Install the exact resolved version instead of the mutable default tag: ```bash "$NPM_BIN" install -g "openclaw@$TARGET_VERSION" \ --registry=https://registry.npmjs.org ``` 3. **Use one explicitly trusted registry** - Specify `https://registry.npmjs.org` for both metadata resolution and installation. - Do not silently use an arbitrary registry from user or project npm configuration. - Record and display the effective registry before approval. 4. **Verify package identity and integrity** - Retrieve the package manifest and expected `dist.integrity` value for the exact version. - Download the package tarball, verify its integrity before installation, and ensure the installed artifact corresponds to the approved version. - Where available, verify npm provenance or upstream release signatures. 5. **Control lifecycle-script execution** - Assess whether OpenClaw requires npm lifecycle scripts. - If it does not, install with `--ignore-scripts`. - If lifecycle scripts are required, inspect and verify the exact package artifact before allowing those scripts to execute. 6. **Fail closed** - Do not continue when `TARGET_VERSION` is `unknown`. - Abort if release metadata cannot be retrieved or parsed. - Abort if the resolved package version changes between review and installation. - Verify that the installed version exactly equals `TARGET_VERSION`, ...[truncated 765 chars]
