Skip to content

Update stacked: 8 packages - #514

Merged
twitchyliquid64 merged 10 commits into
mainfrom
update-stacked-2026-07-23-ad5d959f
Jul 23, 2026
Merged

Update stacked: 8 packages#514
twitchyliquid64 merged 10 commits into
mainfrom
update-stacked-2026-07-23-ad5d959f

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update base-soup (8 packages)

Note

These packages declare replace_on_cycle in their build.ncl, so
they participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.

Warning

1 requested member did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure (a survivor built against a dropped member's
old version would be a broken closure).

Package Old Target Why
gopls 0.21.1 0.48.0 update failed: download failed with status 404 Not Found

Caution

Pkgscan: 5 new signals introduced across bundle members.
Each member's diff was compared against its prior version. Review carefully — base-soup updates touch the toolchain core, so a malicious bump here has cascade-wide impact.

Package Severity File Line Capability (MBC) Pattern
probe-rs HIGH probe-rs-debug/tests/debug-unwind-tests/stm32u585_hardfault_fp.elf 0 anti-static-analysis/embedded-blob ELF executable in source
probe-rs HIGH probe-rs-debug/tests/debug-unwind-tests/stm32u585_psp_exception.elf 0 anti-static-analysis/embedded-blob ELF executable in source
probe-rs HIGH probe-rs-debug/tests/debug-unwind-tests/stm32u585_nested_exceptions.elf 0 anti-static-analysis/embedded-blob ELF executable in source
probe-rs HIGH probe-rs-debug/tests/debug-unwind-tests/stm32u585_exception_no_debuginfo.elf 0 anti-static-analysis/embedded-blob ELF executable in source
sops MEDIUM sops (upstream release) 0 metadata/recent-bump upstream release <12h ago

Note

Build risk — 2 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.

Bundle member Dependents
claude-code 1 — claude-code-minimal-plugin
uv 1 — diffoscope

Summary

Package Old New Source
capy 0.8.0 0.9.0 github:capysc/capy-cli:operator-pinned
claude-code 2.1.216 2.1.218 override:claude-code:operator-pinned
codex 0.144.6 0.145.0 github:openai/codex:tag:operator-pinned
uv 0.11.30 0.11.31 github:astral-sh/uv:operator-pinned
kubectl 1.36.2 1.36.3 github:kubernetes/kubernetes:operator-pinned
probe-rs 0.31.0 0.32.0 github:probe-rs/probe-rs:operator-pinned
sops 3.13.2 3.13.3 github:getsops/sops:operator-pinned
syft 1.48.0 1.49.0 github:anchore/syft:operator-pinned

Per-package details

capy 0.8.0 → 0.9.0
  • SHA256: 979a9e73d4db3f17...3257d7d0652d1df2...
  • Size: 4.6 MB
  • Source: https://github.com/capysc/capy-cli/archive/refs/tags/v0.8.0.tar.gzhttps://github.com/capysc/capy-cli/archive/refs/tags/v0.9.0.tar.gz
  • Released: 1 days ago (2026-07-22)
  • License: AGPL-3.0-only (source: tarball)
claude-code 2.1.216 → 2.1.218
  • SHA256: 74deca45220b8080...e12071751a9336b8...
  • Size: 273.2 MB
  • Source: https://storage.googleapis.com/claude-code-dist-86c565f3-f756-42ad-8dfa-d59b1c096819/claude-code-releases/2.1.216/linux-x64/claude%{gcs_bucket}/2.1.218/linux-x64/claude
  • Released: unknown (non-GitHub source or tag-only fallback)
codex 0.144.6 → 0.145.0
  • SHA256: f2e8395538dc15fa...7126822e9148f202...
  • Size: 10.0 MB
  • Source: https://github.com/openai/codex/archive/refs/tags/rust-v0.144.6.tar.gzhttps://github.com/openai/codex/archive/refs/tags/rust-v0.145.0.tar.gz
  • Released: unknown (non-GitHub source or tag-only fallback)
  • License: Apache-2.0 (source: GitHub + tarball)
uv 0.11.30 → 0.11.31
  • SHA256: ff895fff1c218fca...57a268b4178270ee...
  • Size: 7.4 MB → 7.4 MB
  • Source: gs://minimal-staging-archives/uv-0.11.30.tar.gzgs://minimal-staging-archives/uv-0.11.31.tar.gz
  • Released: 1 days ago (2026-07-22)
  • License: MIT OR Apache-2.0 (source: GitHub + tarball)
kubectl 1.36.2 → 1.36.3
  • SHA256: ffbc46612cf32ad0...950f7dd65b64b18c...
  • Size: 40.6 MB
  • Source: https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.36.2.tar.gzhttps://github.com/kubernetes/kubernetes/archive/refs/tags/v1.36.3.tar.gz
  • Released: 15 hours ago (2026-07-23)
  • License: Apache-2.0 (source: GitHub + tarball)
probe-rs 0.31.0 → 0.32.0
  • SHA256: 7a5022d6956daaa8...9c4ba2046d4709f6...
  • Size: 18.8 MB
  • Source: https://github.com/probe-rs/probe-rs/archive/refs/tags/v0.31.0.tar.gzhttps://github.com/probe-rs/probe-rs/archive/refs/tags/v0.32.0.tar.gz
  • Released: 17 hours ago (2026-07-22)
  • License: MIT OR Apache-2.0 (source: GitHub + tarball)
sops 3.13.2 → 3.13.3
  • SHA256: 79560b53814e2003...49811c5ed80f6b4d...
  • Size: 272 KB → 273 KB
  • Source: gs://minimal-staging-archives/getsops/sops/v3.13.2.tar.gzgs://minimal-staging-archives/getsops/sops/v3.13.3.tar.gz
  • Released: 10 hours ago (2026-07-23)
  • License: MPL-2.0 (source: GitHub + tarball)
syft 1.48.0 → 1.49.0
  • SHA256: ee757ade3c9804fd...7fa1d225a50be61a...
  • Size: 7.2 MB → 7.2 MB
  • Source: gs://minimal-staging-archives/anchore/syft/v1.48.0.tar.gzgs://minimal-staging-archives/anchore/syft/v1.49.0.tar.gz
  • Released: 2 days ago (2026-07-21)
  • License: Apache-2.0 (source: GitHub + tarball)

Created by pkgmgr

The 0-to-new-version bump pulled in @napi-rs/keyring, which ships
`.node` ELF shared libraries inside node_modules
(keyring.linux-{arm64,x64}-gnu.node). The output-types checker
correctly refused the inert OutputData claim on both arches:

    data output "node_modules" matched binary/library file
    usr/lib/node_modules/@capysc/cli/node_modules/@napi-rs/…/keyring….node

Those are real loadable code, so declare them as such —
`allow_executable = true` on the node_modules output, the exact shape
cf (the other node package with executable module content) already
uses. Checker intent preserved: the escape is explicit and reviewed,
not silent.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@twitchyliquid64
twitchyliquid64 marked this pull request as ready for review July 23, 2026 19:48
@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Jul 23, 2026
Merged via the queue into main with commit ad42643 Jul 23, 2026
9 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-stacked-2026-07-23-ad5d959f branch July 23, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants