Require strict ISO 8601 in the age backstop; document the no-stable-release stance

GNU date accepts relative expressions like '2 days ago', which would let a
buggy hook fabricate a release age; the backstop now insists on an ISO 8601
timestamp before date parses it. The provider header now states, rather than
contradicts, the code's behavior for a feed with no stable releases: that is
a loud failure by design, while quarantined releases report no update.
This commit is contained in:
Ryan Hughes
2026-08-24 20:32:20 -04:00
parent fd03757f22
commit 92735d5539
2 changed files with 15 additions and 3 deletions
+4 -2
View File
@@ -29,8 +29,10 @@ package_upstream_github_repo() {
# Fetches sit behind functions so the self-test can replace them with fixture
# readers; everything below the fetch is deterministic and testable offline.
# Only the 100 most recent releases are considered -- a bounded search, not
# pagination. A feed whose entire first page is drafts, prereleases, or
# quarantined releases reports no update and waits for the next run.
# pagination. Quarantined releases report no update and wait for the next
# run; a page with no stable release at all (drafts and prereleases only)
# fails the sync instead, because a provider-tracked feed suddenly shipping
# nothing stable is an anomaly worth a loud error, not a silent skip.
github_fetch_releases() {
local repo="$1"
curl -fsSL "https://api.github.com/repos/$repo/releases?per_page=100"