Skip to content

Update stacked: 2 packages - #571

Merged
twitchyliquid64 merged 4 commits into
mainfrom
update-stacked-2026-08-05-34ce88a8
Aug 6, 2026
Merged

Update stacked: 2 packages#571
twitchyliquid64 merged 4 commits into
mainfrom
update-stacked-2026-08-05-34ce88a8

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update base-soup (2 packages)

Note

These packages declare replace_on_cycle in their build.ncl, so
they participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.

Warning

Pkgscan: 1 new signal introduced across bundle members.
Each member's diff was compared against its prior version. Review carefully — base-soup updates touch the toolchain core, so a malicious bump here has cascade-wide impact.

Package Severity File Line Capability (MBC) Pattern
python MEDIUM python (upstream release) 0 metadata/recent-bump upstream release <12h ago

Note

Build risk — 50 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.

Bundle member Dependents
python 48 — android-sdk, boost, bun, cabal, cython, ddgr, deno, diffoscope (+40 more)
flit-core 2 — pyproject-hooks, pyproject-metadata

Summary

Package Old New Source
python 3.14.6 3.14.7 github:python/cpython:tag:operator-pinned
flit-core 3.12.0 4.0.2 github:pypa/flit:tag:operator-pinned

Vulnerabilities fixed (7)

Package CVE / GHSA CPE Severity Fixed in
python CVE-2026-11940 (python, python) HIGH via range: < 3.15.0b4; fixed in commits 27dd970 / 672825e / 771d12d / 79c06bd / be13e86
python CVE-2026-11972 (python, python) HIGH via range: < 3.15.0b4; fixed in commits 3f031d4 / 4ce6bf7 / 7f0dc59 / e86666c / eb63c0f / f…
python CVE-2026-15308 (python, python) HIGH 3.15.0
python CVE-2025-15366 (python, python) MEDIUM via range: < 3.15.0a6; fixed in commits 6262704 / d0921ef / f2cd7ef / 2981822 / 71926d9
python CVE-2026-0864 (python, python) MEDIUM via range: < 3.15.0b4; fixed in commits 5858e42 / 0adb386 / 71f2e02 / aaf850f / 27dd970
python CVE-2026-12003 (python, python) MEDIUM via range: < 3.15.0b3; fixed in commits 16c40f9 / 9e863fa / a86de0b / b93d6d3
python CVE-2026-6879 (python, python) LOW via range: fixed in commits 02c08e6 / 2ffab08 / 390337b / cb40934; fixed in commits 2ffab08…

Warning

4 known vulnerabilities still affect this bundle after update. Run pkgmgr vulns for details.

Per-package details

python 3.14.6 → 3.14.7
  • SHA256: 143b1dddefaec3bd...3b48dac8fb59f62e...
  • Size: 23.9 MB → 24.1 MB
  • Source: gs://minimal-staging-archives/Python-3.14.6.tar.xzgs://minimal-staging-archives/Python-3.14.7.tar.xz
  • Released: 6 hours ago (2026-08-05)
  • License: Python-2.0.1 (source: tarball)
flit-core 3.12.0 → 4.0.2
  • SHA256: 18f63100d6f94385...b6929defd93884b5...
  • Size: 53 KB
  • Source: https://pypi.org/packages/source/f/flit-core/flit_core-3.12.0.tar.gzhttps://pypi.org/packages/source/f/flit-core/flit_core-4.0.2.tar.gz
  • Released: 20 hours ago (2026-08-04)
  • License: BSD-3-Clause (source: GitHub + tarball)

Created by pkgmgr

@twitchyliquid64

Copy link
Copy Markdown
Member

Cancelled build bc a full rebuild will take a while and we have stuff to do today. Will kick off again tonight

@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Aug 6, 2026
Merged via the queue into main with commit fc30c28 Aug 6, 2026
9 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-stacked-2026-08-05-34ce88a8 branch August 6, 2026 03:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant