Files
msd-core/.changeset/fix-3130-update-npx-robust.md
Tom Boucher 3e2682d3c9 fix(#3130): harden update.md npx invocations against cache-stale and token-routing failures (#3136)
* fix(#3130): harden update.md npx invocations against cache-stale and token-routing

Two failure modes with the old form:
1. Cache-stale: npx serves a cached older version (no --package= flag)
2. Token-routing: Bash-tool wrapper misroutes @ token in package@tag spec

All three sibling invocations (local/global/unknown) now use:
  npx -y --package=get-shit-done-cc@latest -- get-shit-done-cc $ARGS

--package= forces a fresh registry fetch; -- prevents token misrouting.

Also fixes the manual-update hint in the error-exit block.

Regression test: tests/bug-3130-update-npx-robust-invocation.test.cjs
Suite: 6973/6973 pass. Closes #3130.

* fix(lint): allow-test-rule for update.md structural contract test
2026-05-05 15:01:59 -04:00

630 B

type, pr
type pr
Fixed 3130

update.md npx invocations hardened against cache-stale and Bash-tool token-routing failures — the previous npx -y get-shit-done-cc@latest form had two failure modes: (1) npx serving a cached older version instead of @latest, and (2) Bash-tool wrappers misrouting the @ token, producing Unknown command: "get-shit-done-cc@latest". All three sibling invocations (local, global, unknown/fallback) now use npx -y --package=get-shit-done-cc@latest -- get-shit-done-cc — the --package= flag forces a fresh registry fetch and the -- separator prevents token misrouting. Closes #3130.