Skip to content

feat: automatically update the active CLI install - #127

Merged
justinhelmer merged 1 commit into
mainfrom
fix/automatic-updates
Oct 9, 2026
Merged

justinhelmer merged 1 commit into
mainfrom
fix/automatic-updates

Conversation

@justinhelmer

Copy link
Copy Markdown
Contributor

polylane update currently only prints commands, so installed CLIs stay stale until a user updates them manually. This change detects the active install and updates it without a prompt, either on demand or after a successful command at most once per day.

npm, Bun, and Homebrew installs use the owning package manager. Standalone installs verify the release checksum and version before replacing the bundle. The current command keeps its original version and result; the next command uses the update. Update output stays on stderr. CI, development, unknown installs, automatic opt-outs, prerelease builds, and active version pins are preserved.

Validation at e21f050:

  • Failing-before regression proved the old update command left the installed bundle unchanged; passing-after tests cover replacement, checksum/version rejection, dry run, caching, concurrent checks, install ownership, pins, opt-out, and clean JSON through the bundled CLI.
  • 566 tests, typecheck, lint, build, and executable smoke passed locally. The 16 update tests also passed on Node 20.
  • Read-only detection correctly identified the two real installs on the development machine. A disposable standalone install successfully downloaded and verified the public v0.2.49 release.
  • Package-manager upgrades use local executable fixtures; no real global installation was changed. Merge and release have not occurred.

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No verdict submitted — not approving.

Reviewed at e21f050.

For agents

Full review

Review blocked by a preflight infrastructure failure: git rev-parse HEAD returned no completion receipt (metadata_unavailable), so I could not confirm the checkout matches e21f050a832cea98bf103cc735cc70a41ef7804d. I stopped without submitting findings or a verdict.

@polylane

polylane Bot commented Oct 9, 2026

Copy link
Copy Markdown

Warning

Polylane could not verify the production impact of this pull request.

No production resource runs or consumes this CLI: coreplanelabs/cli is a Node CLI shipped via npm, Homebrew, and GitHub releases, and the release workflow is tag-triggered, so merging publishes nothing. CI and dev installs skip the auto-update, and a code search across the cloud accounts found no global install of the CLI.

View the full analysis →

Also considered · 3 refuted
  • Refuted · Automatic self-update drifts the CLI inside production sandboxes or CI · isCI() and the dev/unknown short-circuits mean the automatic path never runs on the platform's CI or on repo checkouts, and no production image or worker carries a global CLI install to update.
  • Refuted · Merging publishes a new CLI version to production clients · release.yml fires on push: tags: v* only, so merging to main runs checks and publishes nothing; the change cannot reach production clients on merge.
  • Refuted · Standalone update replaces the running bundle and corrupts the install · The replacement path is guarded by checksum, version, and a stat recheck with an atomic rename on the end-user machine; it touches no attached cloud resource.
Analysed against 8 cloud accounts and 1 repository
  • Cloud accounts: coreplane-prod, baseberry-uat, coreplane-infra, coreplane, coreplane-gtm, 251714435813, Polylane, coreplanelabs
  • Repository: coreplanelabs/cli

View in Polylane Disable reviews

Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to.

Connect resources

Polylane analysed e21f050 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

@justinhelmer

Copy link
Copy Markdown
Contributor Author

@claude review PR #127 at exact head e21f050 against REVIEW.md. Run the repo checks and clean build smoke, verify the PR claims, and post findings inline. Focus on active-install ownership, concurrent updates, version pins, and command output/result preservation. Do not edit, push, merge, or release.

The Switchboard review stopped before source review because its mandatory checkout command returned metadata_unavailable. Node 20, 22, and 24 CI passed at this head. A local independent reviewer is also checking the same head; the parent owns all fixes.

@justinhelmer justinhelmer left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: No Important issues found in the automatic updater at e21f050.

Independent Codex review. Read the full 11-file diff against base 917d99b, swept references for every changed function, checked PR-body behavior claims, and made a second adversarial pass over installation detection, version pins, concurrency, child execution, and command output/result preservation.

From a disposable detached checkout: npm ci, live codegen, typecheck, lint, and all 566 tests passed on Node 26.6.0. A clean-environment build and executable version smoke passed. All 16 updater and bundled-CLI tests also passed on Node 20, 22, and 24. Package-manager mutation remains fixture-based; no real global installation was changed. Real Homebrew formula/pin-list source and Bun's documented commands support the manager assumptions. Windows update behavior was read but not executed locally.

This is a COMMENT-state review under the authenticated human identity, not an author approval or a review-bot identity. Merge, release, deployment, and live update acceptance are separate.

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: no issues found

Reviewed at e21f050.

For agents

Rationale: No consequential source defects found at e21f050; requested local tests and clean-build smoke were not performed due to runtime restrictions.

Full review

No qualifying source findings; local typechecking was blocked by missing generated files, and this runtime prohibits the requested dependency installation, tests, and clean-build smoke.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). A repo admin enabled this via the auto-approve workflow.

@justinhelmer
justinhelmer merged commit d30e5e0 into main Oct 9, 2026
7 checks passed
@justinhelmer
justinhelmer deleted the fix/automatic-updates branch October 9, 2026 00:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant