Skip to content

Update stacked: 8 packages - #606

Open
gominimal-pkgmgr-mgr[bot] wants to merge 9 commits into
mainfrom
update-stacked-2026-08-14-26edbad7
Open

Update stacked: 8 packages#606
gominimal-pkgmgr-mgr[bot] wants to merge 9 commits into
mainfrom
update-stacked-2026-08-14-26edbad7

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update base-soup (8 packages)

Note

These packages declare replace_on_cycle in their build.ncl, so
they participate in the toolchain rebuild graph and one hash change
cascades through the set. Bundling ensures the cascading rebuild
lands as a single unit, even when only one package is bumping —
avoids back-to-back full rebuilds from singleton PRs.

Warning

2 requested members did NOT ship — each needs separate follow-up.
A member is dropped when it fails to update, has its gs:// mirror
withheld by the scan gate, or is peeled to keep the shipped set a
closed dependency closure. Reasons are abbreviated — the full
diagnostics ride the Slack thread and the run's logs.

Package Old Target Why
llama.cpp b10357 b10433 held for dwell — the release is too fresh (anti-xz recency gate) and the gs:// mirror write was withheld.
railway 5.35.1 5.41.0 gs:// mirror withheld (pkgscan-critical).
Pkgscan: 1 below-threshold signal across bundle members (all Info severity, risk score 0.1). Demoted in benign contexts (test fixtures, CI workflow setup); expand for details.
Package Severity File Line Capability (MBC) Pattern
nss INFO nss (upstream release) 0 metadata/recent-bump recency NOT evaluated — no release date from the version source

Note

Build risk — 53 dependents across the tree. Package(s) that
build- or runtime-depend on a member of this bundle may need a rebuild,
or could FTBFS on an API/ABI change. Informational (not blocking) — a
heads-up for the reviewer on what this bump can ripple into.

Bundle member Dependents
go 45 — act, age, bun, caddy, chezmoi, cloud-sql-proxy, cloudflared, cosign (+37 more)
harfbuzz 5 — chromium-bin, chromium-headless-shell-bin, ffmpeg, libass, pango
nss 2 — chromium-bin, chromium-headless-shell-bin
uv 1 — diffoscope

Summary

Package Old New Source
go 1.26.5 1.26.6 github:golang/go:tag:operator-pinned
harfbuzz 14.3.0 14.3.1 github:harfbuzz/harfbuzz:release-asset:operator-pinned
nss 3.126 3.126.1 override:nss:operator-pinned
bottom 0.14.7 0.14.8 github:ClementTsang/bottom:operator-pinned
uv 0.12.3 0.12.4 github:astral-sh/uv:operator-pinned
govulncheck 1.6.0 1.7.0 github:golang/vuln:tag:operator-pinned
pulumi 3.256.0 3.257.0 github:pulumi/pulumi:operator-pinned
ruff 0.16.2 0.16.3 github:astral-sh/ruff:operator-pinned

Warning

1 known vulnerabilities still affect this bundle after update. Run pkgmgr vulns for details.

Per-package details

go 1.26.5 → 1.26.6
  • SHA256: 5c2c3b16caefa1d9...708effb774be8237...
  • Size: 66.9 MB
  • Source: https://go.dev/dl/go1.26.5.linux-amd64.tar.gzvariants.amd64_url
  • Released: 1 days ago (2026-08-13)
  • License: BSD-3-Clause (source: GitHub + tarball)
harfbuzz 14.3.0 → 14.3.1
  • SHA256: 16070d77cfc4ba1f...9dae9538aae2ffdf...
  • Size: 19.8 MB → 19.8 MB
  • Source: gs://minimal-staging-archives/harfbuzz-14.3.0.tar.xzgs://minimal-staging-archives/harfbuzz-14.3.1.tar.xz
  • Released: 1 days ago (2026-08-12)
  • License: MIT-Modern-Variant (source: tarball)
nss 3.126 → 3.126.1
  • SHA256: 7aa07c758be1453d...d5fcd5e3ee92b9dd...
  • Size: 78.8 MB → 78.8 MB
  • Source: gs://minimal-staging-archives/nss-3.126.tar.gzgs://minimal-staging-archives/nss-3.126.1.tar.gz
  • Released: unknown (non-GitHub source or tag-only fallback)
  • License: MPL-2.0 (source: tarball)
bottom 0.14.7 → 0.14.8
  • SHA256: 249fca7809224602...be10adada9ec1e5d...
  • Size: 3.5 MB → 3.5 MB
  • Source: gs://minimal-staging-archives/ClementTsang/bottom/0.14.7.tar.gzgs://minimal-staging-archives/ClementTsang/bottom/0.14.8.tar.gz
  • Released: 1 days ago (2026-08-13)
  • License: MIT (source: GitHub + tarball)
uv 0.12.3 → 0.12.4
  • SHA256: 7d95d35a941135b9...49d16c1451d69309...
  • Size: 7.3 MB → 8.6 MB
  • Source: gs://minimal-staging-archives/uv-0.12.3.tar.gzgs://minimal-staging-archives/uv-0.12.4.tar.gz
  • Released: 22 hours ago (2026-08-13)
  • License: MIT OR Apache-2.0 (source: GitHub + tarball)
govulncheck 1.6.0 → 1.7.0
  • SHA256: 70f82d70f3a6757b...4fb7f0204b7e039f...
  • Size: 6.4 MB
  • Source: https://github.com/golang/vuln/archive/refs/tags/v1.6.0.tar.gzhttps://github.com/golang/vuln/archive/refs/tags/v1.7.0.tar.gz
  • Released: 1 days ago (2026-08-13)
  • License: BSD-3-Clause (source: GitHub + tarball)
pulumi 3.256.0 → 3.257.0
  • SHA256: 43887337b91f4d61...e51055e520184b99...
  • Size: 20.1 MB → 20.3 MB
  • Source: gs://minimal-staging-archives/pulumi/pulumi/v3.256.0.tar.gzgs://minimal-staging-archives/pulumi/pulumi/v3.257.0.tar.gz
  • Released: 1 days ago (2026-08-13)
  • License: Apache-2.0 (source: GitHub + tarball)
ruff 0.16.2 → 0.16.3
  • SHA256: 480cd1332b218840...1eecc23082f91b6b...
  • Size: 12.8 MB → 12.9 MB
  • Source: gs://minimal-staging-archives/astral-sh/ruff/0.16.2.tar.gzgs://minimal-staging-archives/astral-sh/ruff/0.16.3.tar.gz
  • Released: 1 days ago (2026-08-13)
  • License: MIT (source: GitHub)

Created by pkgmgr

…rin failure

No source change. The amd64 tamarin-prover failure (alex version detection)
is either a store race under --jobs=$(nproc), which is intermittent, or
something deterministic. Re-running the identical tree distinguishes them,
which is the one fact pkgs#609 is reasoning without.

Expected to fail again — tamarin on main is still broken. What matters is
WHETHER it fails the same way.
bryan-minimal added a commit that referenced this pull request Aug 14, 2026
…aming

The previous commit said tamarin "builds on arm64 and fails on amd64", and
treated it as the onboarding's amd64-unverified flag finally coming due. That
was wrong, and wrong in a way that would mislead the next reader.

pkgs#607 and #608 built the SAME tamarin source on the SAME amd64 builder and
passed — merged 20:28 and 20:30 on 2026-08-14, hours after #606 failed at
12:33. So amd64 works most of the time. It is not a miscompile, not a missing
dependency, and not something #606 introduced: it is a race, and #606 drew the
short straw.

This strengthens the fix rather than weakening it — removing cabal's own
store-provisioned alex removes the racy step — but the diagnosis in the comment
should say what is actually true.

Worth recording why a flake is the worse shape here: the natural response is to
re-run it, which usually works, which is exactly how one survives for weeks
without anyone fixing it. If this change does NOT settle it, the next suspect
is `--jobs=$(nproc)` itself rather than alex specifically, since the same race
can bite any build tool.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant