codekingpro/portable-devtools
115k
1// Separated out for easier unit testing
2module.exports = async (process, validateEngines) => {
3 // set it here so that regardless of what happens later, we don't leak any private CLI configs to other programs
4 process.title = 'npm'
5
6 // Patch the global fs module here at the app level
7 require('graceful-fs').gracefulify(require('node:fs'))
8
9 const satisfies = require('semver/functions/satisfies')
10 const ExitHandler = require('./exit-handler.js')
11 const exitHandler = new ExitHandler({ process })
12 const Npm = require('../npm.js')
13 const npm = new Npm()
14 exitHandler.setNpm(npm)
15
16 // only log node and npm paths in argv initially since argv can contain sensitive info. a cleaned version will be logged later
17 const { log, output } = require('proc-log')
18 log.verbose('cli', process.argv.slice(0, 2).join(' '))
19 log.info('using', 'npm@%s', npm.version)
20 log.info('using', 'node@%s', process.version)
21
22 // At this point we've required a few files and can be pretty sure we don't contain invalid syntax for this version of node.
23 // It's possible a lazy require would, but that's unlikely enough that it's not worth catching anymore and we attach the more important exit handlers.
24 validateEngines.off()
25 exitHandler.registerUncaughtHandlers()
26
27 // It is now safe to log a warning if they are using a version of node that is not going to fail on syntax errors but is still unsupported and untested and might not work reliably.
28 // This is safe to use the logger now which we want since this will show up in the error log too.
29 if (!satisfies(validateEngines.node, validateEngines.engines)) {
30 log.warn('cli', validateEngines.unsupportedMessage)
31 }
32
33 // Now actually fire up npm and run the command.
34 // This is how to use npm programmatically:
35 try {
36 const { exec, command, args } = await npm.load()
37
38 if (!exec) {
39 return exitHandler.exit()
40 }
41
42 if (!command) {
43 output.standard(npm.usage)
44 process.exitCode = 1
45 return exitHandler.exit()
46 }
47
48 // Options are prefixed by a hyphen-minus (-, \u2d).
49 // Other dash-type chars look similar but are invalid.
50 const nonDashArgs = npm.argv.filter(a => /^[\u2010-\u2015\u2212\uFE58\uFE63\uFF0D]/.test(a))
51 if (nonDashArgs.length) {
52 log.error(
53 'arg',
54 'Argument starts with non-ascii dash, this is probably invalid:',
55 require('@npmcli/redact').redactLog(nonDashArgs.join(', '))
56 )
57 }
58
59 const execPromise = npm.exec(command, args)
60
61 // this is async but we don't await it, since its ok if it doesnt finish before the command finishes running.
62 // it uses command and argv so it must be initiated here, after the command name is set
63 const updateNotifier = require('./update-notifier.js')
64 // eslint-disable-next-line promise/catch-or-return
65 updateNotifier(npm).then((msg) => (npm.updateNotification = msg))
66
67 await execPromise
68 return exitHandler.exit()
69 } catch (err) {
70 return exitHandler.exit(err)
71 }
72}
73 