| 204 | |
| 205 | |
| 206 | def main() -> None: |
| 207 | version = _version() |
| 208 | bin_path = _bin_path(version) |
| 209 | |
| 210 | if not bin_path.exists(): |
| 211 | bin_path = _download(version) |
| 212 | |
| 213 | # args is a list (not a shell string), so exec/subprocess treat each |
| 214 | # element as a discrete argv entry — no shell interpretation, no |
| 215 | # injection vector. sys.argv forwarding is the whole point of this |
| 216 | # shim, so tainted-input suppression is intentional. |
| 217 | args = [str(bin_path)] + sys.argv[1:] |
| 218 | |
| 219 | if sys.platform != "win32": |
| 220 | os.execv(str(bin_path), args) # noqa: S606 — list form, no shell |
| 221 | else: |
| 222 | import subprocess |
| 223 | result = subprocess.run(args) # noqa: S603 — list form, no shell=True |
| 224 | sys.exit(result.returncode) |