fix(npx)!: detect new `npx` versions and fail gracefully (#10452)
BREAKING CHANGE: the `npx` plugin used a feature of `npx` to check for
npm packages and run them if a command was not found. This feature was
removed in v7.0.0 and was deemed insecure. The `npx` plugin is now
officially deprecated and will be removed soon.
Fixes #10452
Diff
1diff --git a/plugins/npx/README.md b/plugins/npx/README.md
2index 41e4c1352f4551207a2e467a8767d655ae43a35f..4b2aba8f0bd70a8a1055dedc5a26039346334254 100644
3--- a/plugins/npx/README.md
4+++ b/plugins/npx/README.md
5@@ -1,27 +1,4 @@
6-# NPX Plugin
7-
8-> npx(1) -- execute npm package binaries. ([more info](https://github.com/npm/npx))
9-
10-This plugin automatically registers npx command-not-found handler if `npx` exists in your `$PATH`.
11-
12-To use it, add `npx` to the plugins array in your zshrc file:
13-
14-```zsh
15-plugins=(.... npx)
16-```
17-
18-## Note
19-
20-The shell auto-fallback doesn't auto-install plain packages. In order to get it to install something, you need to add `@`:
21-
22-```
23-➜ jasmine@latest # or just `jasmine@`
24-npx: installed 13 in 1.896s
25-Randomized with seed 54385
26-Started
27-```
28-
29-It does it this way so folks using the fallback don't accidentally try to install regular typoes.
30+# npx plugin
3132 ## Deprecation
3334diff --git a/plugins/npx/npx.plugin.zsh b/plugins/npx/npx.plugin.zsh
35index 32bb67377a0db4c22832b24e12ed46afbb0eabc0..c1e2eca9889c21574db0385908c1c5b0f33c40b1 100644
36--- a/plugins/npx/npx.plugin.zsh
37+++ b/plugins/npx/npx.plugin.zsh
38@@ -1,7 +1,12 @@
39-# NPX Plugin
40-# https://www.npmjs.com/package/npx
41-# Maintainer: Pooya Parsa <pooya@pi0.ir>
42+if (( ! $+commands[npx] )); then
43+ return
44+fi
4546-(( $+commands[npx] )) && {
47- source <(npx --shell-auto-fallback zsh)
48-}
49+if ! npx_fallback_script="$(npx --shell-auto-fallback zsh 2>/dev/null)"; then
50+ print -u2 ${(%):-"%F{yellow}This \`npx\` version ($(npx --version)) is not supported.%f"}
51+else
52+ source <(<<< "$npx_fallback_script")
53+fi
54+
55+print -u2 ${(%):-"%F{yellow}The \`npx\` plugin is deprecated and will be removed soon. %BPlease disable it%b.%f"}
56+unset npx_fallback_script
57diff --git a/plugins/osx/osx.plugin.zsh b/plugins/osx/osx.plugin.zsh
58index 9304e7f322b14d14250576ccf26dd22b4af1bd63..3b09359814822f676c02daf03d965fbf68d3dfb9 100644
59--- a/plugins/osx/osx.plugin.zsh
60+++ b/plugins/osx/osx.plugin.zsh
61@@ -1,5 +1,5 @@
62-print ${(%):-'%F{yellow}The `osx` plugin is deprecated and has been renamed to `macos`.'}
63-print ${(%):-'Please update your .zshrc to use the `%Bmacos%b` plugin instead.%f'}
64+print -u2 ${(%):-'%F{yellow}The `osx` plugin is deprecated and has been renamed to `macos`.'}
65+print -u2 ${(%):-'Please update your .zshrc to use the `%Bmacos%b` plugin instead.%f'}
6667 (( ${fpath[(Ie)$ZSH/plugins/macos]} )) || fpath=("$ZSH/plugins/macos" $fpath)
68 source "$ZSH/plugins/macos/macos.plugin.zsh"