diff --git a/.changeset/mellow-pandas-rally.md b/.changeset/mellow-pandas-rally.md new file mode 100644 index 000000000..303932cce --- /dev/null +++ b/.changeset/mellow-pandas-rally.md @@ -0,0 +1,5 @@ +--- +type: Security +pr: 3032 +--- +**Production dependency tree is clear of known advisories** — three transitive packages reached by `@anthropic-ai/claude-agent-sdk` carried published advisories: `fast-uri` (host confusion via a backslash authority introducer), `ip-address` (three SSRF / trust-boundary bypasses via leading-zero octets, CIDR-suffix suppression, and IPv4-mapped address misclassification), and `hono`. All three are lockfile-only, semver-in-range updates. (#2755) diff --git a/.changeset/sturdy-zebras-purr.md b/.changeset/sturdy-zebras-purr.md new file mode 100644 index 000000000..0c51a0155 --- /dev/null +++ b/.changeset/sturdy-zebras-purr.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 3032 +--- +**A `--kimi-code` install now configures hooks in Kimi Code, not Kimi CLI** — installing GSD for Kimi Code wrote its lifecycle hooks, hook bundle and CommonJS marker into Kimi CLI's `~/.kimi/config.toml`, so Kimi Code itself received no hooks at all and a machine with only Kimi Code got a config file no product reads. Each Kimi product now uses its own root and its own environment override (`KIMI_SHARE_DIR` for Kimi CLI, `KIMI_CODE_HOME` for Kimi Code), and uninstalling one no longer removes the other's hooks. (#2755) diff --git a/bin/install.js b/bin/install.js index eaee3797c..652672ef1 100755 --- a/bin/install.js +++ b/bin/install.js @@ -8082,11 +8082,12 @@ function uninstall(isGlobal, runtime = DEFAULT_RUNTIME) { // 1a-kimi. Non-layout Kimi side-effect (#2095 EoS/kimi Upgrade 1): kimi's // native config.toml lives outside targetDir entirely (resolveKimiHooksTomlDir - // resolves ~/.kimi, a sibling of targetDir's ~/.config/agents), so its + // resolves ~/.kimi for kimi and ~/.kimi-code for kimi-code (#2755), a sibling + // of targetDir's ~/.config/agents), so its // cleanup can't be driven by anything under targetDir the way every other // hook surface above is. if (resolveInstallPlan(runtime).hooksSurface === 'kimi-hooks-toml') { - const kimiHooksRoot = resolveKimiHooksTomlDir(); + const kimiHooksRoot = resolveKimiHooksTomlDir({ runtime }); const kimiHooksTomlPath = path.join(kimiHooksRoot, 'config.toml'); const kimiHooksCleanup = removeKimiHooksToml(kimiHooksTomlPath); if (kimiHooksCleanup.changed) { @@ -11924,7 +11925,8 @@ function install(isGlobal, runtime = DEFAULT_RUNTIME, options = {}) { // hooks needed. Kimi is also artifact-only for its INSTALL surface (skills + // kimi-agents, no settings.json) but #2095 Upgrade 1 gives it its own // independent hooksSurface: kimi's native config.toml [[hooks]] array, which - // lives outside targetDir entirely (resolveKimiHooksTomlDir resolves ~/.kimi, + // lives outside targetDir entirely (resolveKimiHooksTomlDir resolves the + // per-runtime root — ~/.kimi for kimi, ~/.kimi-code for kimi-code, #2755 — // a sibling of targetDir's ~/.config/agents) — hence writing it here, inside // this early-return, rather than requiring installSurface to change. // @@ -11945,7 +11947,7 @@ function install(isGlobal, runtime = DEFAULT_RUNTIME, options = {}) { // ~/.kimi/hooks/