惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 聂微东
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
美团技术团队
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
罗磊的独立博客
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
The Cloudflare Blog
Stack Overflow Blog
Stack Overflow Blog
N
Netflix TechBlog - Medium
小众软件
小众软件

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(plugins): trust reviewed official npm launch packages...
vincentkoc · 2026-05-03 · via Recent Commits to openclaw:main

@@ -260,43 +260,67 @@ describe("installPluginFromNpmSpec", () => {

260260

});

261261

});

262262263-

it("allows the official Codex npm plugin to spawn its managed app-server", async () => {

264-

const npmRoot = path.join(suiteTempRootTracker.makeTempDir(), "npm");

265-

const warnings: string[] = [];

266-

mockNpmViewAndInstall({

263+

it.each([

264+

{

265+

spec: "@openclaw/acpx",

266+

pluginId: "acpx",

267+

indexJs: `import { spawn } from "node:child_process";\nspawn("codex-acp", []);`,

268+

},

269+

{

267270

spec: "@openclaw/codex",

268-

packageName: "@openclaw/codex",

269-

version: "2026.5.2",

270271

pluginId: "codex",

271-

npmRoot,

272272

indexJs: `import { spawn } from "node:child_process";\nspawn("codex", ["app-server"]);`,

273-

});

274-275-

const result = await installPluginFromNpmSpec({

276-

spec: "@openclaw/codex",

277-

npmDir: npmRoot,

278-

logger: {

279-

info: () => {},

280-

warn: (msg: string) => warnings.push(msg),

281-

},

282-

});

283-284-

expect(result.ok).toBe(true);

285-

if (!result.ok) {

286-

return;

287-

}

288-

expect(result.pluginId).toBe("codex");

289-

expect(

290-

warnings.some((warning) =>

291-

warning.includes("allowed because it is an official OpenClaw package"),

292-

),

293-

).toBe(true);

294-

expectNpmInstallIntoRoot({

295-

calls: runCommandWithTimeoutMock.mock.calls,

296-

npmRoot,

297-

spec: "@openclaw/codex",

298-

});

299-

});

273+

},

274+

{

275+

spec: "@openclaw/google-meet",

276+

pluginId: "google-meet",

277+

indexJs: `import { spawnSync } from "node:child_process";\nspawnSync("node", ["bridge.js"]);`,

278+

},

279+

{

280+

spec: "@openclaw/voice-call",

281+

pluginId: "voice-call",

282+

indexJs: `import { spawn } from "node:child_process";\nspawn("ngrok", ["http", "3000"]);`,

283+

},

284+

])(

285+

"allows official npm plugin $spec with reviewed launch code",

286+

async ({ spec, pluginId, indexJs }) => {

287+

const npmRoot = path.join(suiteTempRootTracker.makeTempDir(), "npm");

288+

const warnings: string[] = [];

289+

mockNpmViewAndInstall({

290+

spec,

291+

packageName: spec,

292+

version: "2026.5.2",

293+

pluginId,

294+

npmRoot,

295+

indexJs,

296+

});

297+298+

const result = await installPluginFromNpmSpec({

299+

spec,

300+

npmDir: npmRoot,

301+

logger: {

302+

info: () => {},

303+

warn: (msg: string) => warnings.push(msg),

304+

},

305+

});

306+307+

expect(result.ok).toBe(true);

308+

if (!result.ok) {

309+

return;

310+

}

311+

expect(result.pluginId).toBe(pluginId);

312+

expect(

313+

warnings.some((warning) =>

314+

warning.includes("allowed because it is an official OpenClaw package"),

315+

),

316+

).toBe(true);

317+

expectNpmInstallIntoRoot({

318+

calls: runCommandWithTimeoutMock.mock.calls,

319+

npmRoot,

320+

spec,

321+

});

322+

},

323+

);

300324301325

it("rejects non-registry npm specs", async () => {

302326

const result = await installPluginFromNpmSpec({ spec: "github:evil/evil" });