SIGN IN SIGN UP

fix(updater): validate the registry version and never auto-update as root

autoUpdate passed the registry's `dist-tags.latest` string straight into
`npm install -g <name>@<latest>`. compareVersions is lenient by design, so a
value such as "99.0.0 || npm:evil" read as newer and was handed to npm as
written. And there was no root guard: `sudo teamclaude server` ran that
install as root, daily, off a string fetched from the network.

Only a plain x.y.z is installed — anything else is logged and skipped, and
runUpdate itself refuses to spawn for a malformed version (the literal
`latest` used by the manual fallback still passes). Auto-update is skipped
entirely when running as root, with a single log line per process; the
operator can still run `teamclaude update` deliberately. The check, install
kind, installer, package root and uid are injectable so both guards are
tested without npm or a real root.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
M
Mark Karpeles committed
fc563963da1c698ddba7ae49077b6bf7682ffdf9
Parent: a122a4a
Committed by Mark Karpelès <MagicalTux@users.noreply.github.com> on 9/8/2026, 1:35:22 PM