Skip to content

fix(cli): warn and suggest --run-scripts for global packages - #2810

Open
liangmiQwQ wants to merge 10 commits into
voidzero-dev:mainfrom
liangmiQwQ:liang/codex/global-install-scripts
Open

liangmiQwQ wants to merge 10 commits into
voidzero-dev:mainfrom
liangmiQwQ:liang/codex/global-install-scripts

Conversation

@liangmiQwQ

@liangmiQwQ liangmiQwQ commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Close #2766

Global installs and updates skip lifecycle scripts by default. --run-scripts enables all scripts, including transitive dependencies, using the selected Node.js runtime and its bundled npm.

When scripts are skipped, a warning after the installation summaries lists the affected packages and gives a reinstall command. The command preserves an explicitly selected Node.js version. Project-install defaults stay unchanged.

🤖 Generated with Codex

@socket-security

socket-security Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​native-addon@​1.0.0661005880100

View full report

@liangmiQwQ liangmiQwQ changed the title feat(cli): support --ignore-scripts=false for global packages feat(cli): support --run-scripts for global packages Sep 24, 2026
@liangmiQwQ

Copy link
Copy Markdown
Collaborator Author

The reason why I introduce a new --run-scripts instead of --allow-scripts is we must ensure compatibility with different versions of npm, which --allow-scripts is not supported.

@liangmiQwQ liangmiQwQ changed the title feat(cli): support --run-scripts for global packages fix(cli): warn and suggest --run-scripts for global packages Sep 25, 2026
@liangmiQwQ
liangmiQwQ marked this pull request as ready for review September 25, 2026 04:12

@jong-kyung jong-kyung left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💯 All looks good to me

@jong-kyung
jong-kyung requested a review from fengmk2 September 25, 2026 05:53
@fengmk2

fengmk2 commented Sep 25, 2026

Copy link
Copy Markdown
Member

For this case, what option does pnpm require to run scripts directly? I’m wondering if we can implement this without adding a new option.

@liangmiQwQ

Copy link
Copy Markdown
Collaborator Author

For this case, what option does pnpm require to run scripts directly? I’m wondering if we can implement this without adding a new option.

@fengmk2 pnpm / npm 12+ uses --allow-scripts=[...list], this receives a list to control each child dependency. I tried to follow these two existing options but failed, because the current runtime-isolated vp install -g architecture requires us to support different versions of npm, where older npms do not provide that.

@fengmk2

fengmk2 commented Sep 25, 2026

Copy link
Copy Markdown
Member

Let’s hold off on merging this fix for now and revisit the best way to address it after the 1.0 release.

@liangmiQwQ
liangmiQwQ marked this pull request as draft September 25, 2026 06:10
@liangmiQwQ
liangmiQwQ marked this pull request as ready for review September 28, 2026 12:43

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

vp install -g silently skips package lifecycle scripts, breaking script-dependent CLIs

3 participants