Update stacked: 2 packages - #571
Merged
Merged
Conversation
twitchyliquid64
approved these changes
Aug 5, 2026
Member
|
Cancelled build bc a full rebuild will take a while and we have stuff to do today. Will kick off again tonight |
twitchyliquid64
approved these changes
Aug 6, 2026
twitchyliquid64
enabled auto-merge
August 6, 2026 02:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update base-soup (2 packages)
Note
These packages declare
replace_on_cyclein their build.ncl, sothey participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.
Warning
Pkgscan: 1 new signal introduced across bundle members.
Each member's diff was compared against its prior version. Review carefully — base-soup updates touch the toolchain core, so a malicious bump here has cascade-wide impact.
python (upstream release)metadata/recent-bumpupstream release <12h agoNote
Build risk — 50 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.
pythonandroid-sdk,boost,bun,cabal,cython,ddgr,deno,diffoscope(+40 more)flit-corepyproject-hooks,pyproject-metadataSummary
3.14.63.14.7github:python/cpython:tag:operator-pinned3.12.04.0.2github:pypa/flit:tag:operator-pinnedVulnerabilities fixed (7)
(python, python)< 3.15.0b4; fixed in commits 27dd970 / 672825e / 771d12d / 79c06bd / be13e86(python, python)< 3.15.0b4; fixed in commits 3f031d4 / 4ce6bf7 / 7f0dc59 / e86666c / eb63c0f / f…(python, python)3.15.0(python, python)< 3.15.0a6; fixed in commits 6262704 / d0921ef / f2cd7ef / 2981822 / 71926d9(python, python)< 3.15.0b4; fixed in commits 5858e42 / 0adb386 / 71f2e02 / aaf850f / 27dd970(python, python)< 3.15.0b3; fixed in commits 16c40f9 / 9e863fa / a86de0b / b93d6d3(python, python)fixed in commits 02c08e6 / 2ffab08 / 390337b / cb40934; fixed in commits 2ffab08…Warning
4 known vulnerabilities still affect this bundle after update. Run
pkgmgr vulnsfor details.Per-package details
python 3.14.6 → 3.14.7143b1dddefaec3bd...→3b48dac8fb59f62e...gs://minimal-staging-archives/Python-3.14.6.tar.xz→gs://minimal-staging-archives/Python-3.14.7.tar.xzPython-2.0.1(source: tarball)flit-core 3.12.0 → 4.0.218f63100d6f94385...→b6929defd93884b5...https://pypi.org/packages/source/f/flit-core/flit_core-3.12.0.tar.gz→https://pypi.org/packages/source/f/flit-core/flit_core-4.0.2.tar.gzBSD-3-Clause(source: GitHub + tarball)Created by pkgmgr