mirror of
https://github.com/AikidoSec/safe-chain.git
synced 2026-05-26 12:10:49 +00:00
Add uvx as a supported package manager so that `uvx` commands are routed through safe-chain's MITM proxy for malware detection, just like `uv`. Previously, `uvx` bypassed all safe-chain protections. The uvx package manager reuses the existing uv command runner since uvx is functionally equivalent to `uv tool run`. Fixes #268 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
18 lines
418 B
JavaScript
18 lines
418 B
JavaScript
import { runUv } from "../uv/runUvCommand.js";
|
|
|
|
/**
|
|
* @returns {import("../currentPackageManager.js").PackageManager}
|
|
*/
|
|
export function createUvxPackageManager() {
|
|
return {
|
|
/**
|
|
* @param {string[]} args
|
|
*/
|
|
runCommand: (args) => {
|
|
return runUv("uvx", args);
|
|
},
|
|
// For uvx, rely solely on MITM
|
|
isSupportedCommand: () => false,
|
|
getDependencyUpdatesForCommand: () => [],
|
|
};
|
|
}
|