You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
These packages declare replace_on_cycle in their build.ncl, so
they participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.
Warning
3 requested members did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure (a survivor built against a dropped member's
old version would be a broken closure).
Package
Old
Target
Why
pango
1.58.0
1.58.1
update failed: download failed with status 404 Not Found
atuin
18.17.1
18.19.0
gs:// mirror withheld (pkgscan-critical)
pulumi
3.255.0
3.256.0
gs:// mirror withheld (pkgscan-high)
Caution
Pkgscan: 3 new signals introduced across bundle members.
Each member's diff was compared against its prior version. Review carefully — base-soup updates touch the toolchain core, so a malicious bump here has cascade-wide impact.
Package
Severity
File
Line
Capability (MBC)
Pattern
capy
HIGH
capy (upstream release)
0
metadata/recent-bump
upstream release <6h ago
lazygit
MEDIUM
cpu.out
0
anti-static-analysis/embedded-blob
gzip archive
py-packaging
HIGH
py-packaging (upstream release)
0
metadata/recent-bump
upstream release <6h ago
Note
Build risk — 6 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.
happy-lib-2.1.6 is its own tarball (confirmed on Hackage, 200). Our build.sh is a bare ghc --make Setup.hs + ./Setup configure/build with no dependency resolution — self-contained 1.20.x builds fine that way, 2.x can't.
So this isn't a stale pin or a bad sha. The recipe's build model no longer matches upstream's topology, and no version check can see that — only a build can, which is what caught it here.
Follow-up. happy 2.x needs happy-lib added as a second Source, built lib → exe. There's no precedent to copy: alex and happy are our only Hackage packages and both have exactly one source. That deserves its own PR rather than riding an automated bundle.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update base-soup (6 packages)
Note
These packages declare
replace_on_cyclein their build.ncl, sothey participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.
Warning
3 requested members did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure (a survivor built against a dropped member's
old version would be a broken closure).
pango1.58.01.58.1atuin18.17.118.19.0pulumi3.255.03.256.0Caution
Pkgscan: 3 new signals introduced across bundle members.
Each member's diff was compared against its prior version. Review carefully — base-soup updates touch the toolchain core, so a malicious bump here has cascade-wide impact.
capy (upstream release)metadata/recent-bumpupstream release <6h agocpu.outanti-static-analysis/embedded-blobgzip archivepy-packaging (upstream release)metadata/recent-bumpupstream release <6h agoNote
Build risk — 6 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.
pnpmagent-browser,nexthappyghc,haskell-language-serverpy-packagingpy-build,pyproject-metadataSummary
11.19.011.20.0github:pnpm/pnpm:operator-pinned1.20.1.12.1.6github:haskell/happy:operator-pinned0.9.00.9.1github:capysc/capy-cli:operator-pinned0.17.40.17.7github:modem-dev/hunk:operator-pinned0.63.10.64.0github:jesseduffield/lazygit:operator-pinned26.226.3github:pypa/packaging:operator-pinnedPer-package details
pnpm 11.19.0 → 11.20.0b9e49603540d0410...→34e198cb1e432375...https://registry.npmjs.org/pnpm/-/pnpm-11.19.0.tgz→https://registry.npmjs.org/pnpm/-/pnpm-11.20.0.tgzMIT(source: GitHub + tarball)happy 1.20.1.1 → 2.1.68b4e7dc5a6c5fd66...→9b473961010cb567...https://hackage.haskell.org/package/happy-1.20.1.1/happy-1.20.1.1.tar.gz→https://hackage.haskell.org/package/happy-2.1.6/happy-2.1.6.tar.gzBSD-2-Clause(source: tarball)capy 0.9.0 → 0.9.13257d7d0652d1df2...→42b4debf7a8d0b6a...https://github.com/capysc/capy-cli/archive/refs/tags/v0.9.0.tar.gz→https://github.com/capysc/capy-cli/archive/refs/tags/v0.9.1.tar.gzAGPL-3.0-only(source: tarball)hunk 0.17.4 → 0.17.7f37c7e7c492a60f8...→147a23fc72aa6f76...https://github.com/modem-dev/hunk/archive/refs/tags/v0.17.4.tar.gz→https://github.com/modem-dev/hunk/archive/refs/tags/v0.17.7.tar.gzMIT(source: GitHub + tarball)lazygit 0.63.1 → 0.64.0227ff262138440ff...→2d41928fd3c63550...gs://minimal-staging-archives/jesseduffield/lazygit/v0.63.1.tar.gz→gs://minimal-staging-archives/jesseduffield/lazygit/v0.64.0.tar.gzMIT(source: GitHub + tarball)py-packaging 26.2 → 26.3ff452ff5a3e828ce...→94edc256424af387...https://files.pythonhosted.org/packages/source/p/packaging/packaging-26.2.tar.gz→https://files.pythonhosted.org/packages/source/p/packaging/packaging-26.3.tar.gz(Apache-2.0 AND BSD-2-Clause)(source: tarball)Created by pkgmgr