Skip to content

Update fzf to 0.74.1 - #466

Merged
twitchyliquid64 merged 1 commit into
mainfrom
update-fzf-0.74.1
Jul 20, 2026
Merged

Update fzf to 0.74.1#466
twitchyliquid64 merged 1 commit into
mainfrom
update-fzf-0.74.1

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update fzf 0.74.00.74.1

Source: github:junegunn/fzf:operator-pinned
Release: https://github.com/junegunn/fzf/releases/tag/v0.74.1
Changelog: junegunn/fzf@v0.74.0...v0.74.1
Released: 1 days ago (2026-07-18)

Warning

Pkgscan: 1 new signal introduced by this update (risk score 2.0).
Diff against the prior version surfaced patterns that weren't present before. Review carefully before merging — supply-chain attacks land via version-bump injection.

Severity File Line Capability (MBC) Pattern
MEDIUM fzf (upstream release) 0 metadata/recent-bump upstream release <48h ago

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ fzf 0.74.0 0.74.1
~ fzf-upstream 0.74.0 0.74.1

Changes

Old New
Version 0.74.0 0.74.1
SHA256 55ab5f2256edd889... ba37120bbe45966c...
Size 446 KB 452 KB
Source gs://minimal-staging-archives/junegunn/fzf/v0.74.0.tar.gz gs://minimal-staging-archives/junegunn/fzf/v0.74.1.tar.gz
  • License: MIT (source: GitHub + tarball)

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Jul 20, 2026
Merged via the queue into main with commit 7df6194 Jul 20, 2026
9 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-fzf-0.74.1 branch July 20, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant