mise-bin: ship the newest release that has cleared the 24h quarantine

Gating on /releases/latest alone starves updates when mise's near-daily
cadence keeps the newest release perpetually inside the quarantine window:
today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past
24 hours. Walk the release list (drafts and prereleases excluded) and pick
the newest release, by vercmp, whose published_at is at least 24 hours old.

The quarantine guarantee is unchanged: nothing younger than the window ever
ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid
tags or timestamps still fail closed - now for every release in the feed,
plus a hard failure if the feed reports no stable releases at all.
This commit is contained in:
Ryan Hughes
2026-08-24 14:21:41 -04:00
parent cc2413f0f3
commit eca3ce7815
+48 -21
View File
@@ -2,34 +2,61 @@
set -euo pipefail
repo="jdx/mise"
release=$(curl -fsSL "https://api.github.com/repos/$repo/releases/latest")
tag=$(jq -r '.tag_name // empty' <<<"$release")
published_at=$(jq -r '.published_at // empty' <<<"$release")
if [[ ! "$tag" =~ ^v([A-Za-z0-9._+]+)$ ]]; then
echo "Latest mise release has an invalid tag: ${tag:-<empty>}" >&2
exit 1
fi
if [[ -z "$published_at" ]] || ! published_epoch=$(date --date="$published_at" +%s); then
echo "Latest mise release has an invalid published_at: ${published_at:-<empty>}" >&2
exit 1
fi
# Keep a compromised mise release from reaching Omarchy before there has been
# a full day for maintainers and the community to notice and pull it.
# a full day for maintainers and the community to notice and pull it. Walking
# the release list instead of gating on /releases/latest alone means mise's
# near-daily cadence cannot starve updates: the newest release that has
# finished its quarantine ships even while an even newer one is still inside
# it. Nothing younger than the window ever ships without the explicit bypass.
minimum_release_age_seconds=$((24 * 60 * 60))
now=$(date +%s)
if (( now - published_epoch < minimum_release_age_seconds )); then
if [[ "${MISE_BIN_BYPASS_RELEASE_AGE:-}" == "1" ]]; then
echo "Bypassing mise release-age gate for $tag" >&2
else
echo '{}'
exit 0
releases=$(curl -fsSL "https://api.github.com/repos/$repo/releases?per_page=20")
candidates=0
best_tag=""
best_pkgver=""
while IFS=$'\t' read -r tag published_at; do
if [[ ! "$tag" =~ ^v([A-Za-z0-9._+]+)$ ]]; then
echo "mise release has an invalid tag: ${tag:-<empty>}" >&2
exit 1
fi
pkgver=${BASH_REMATCH[1]}
if [[ -z "$published_at" ]] || ! published_epoch=$(date --date="$published_at" +%s); then
echo "mise release $tag has an invalid published_at: ${published_at:-<empty>}" >&2
exit 1
fi
candidates=$((candidates + 1))
if (( now - published_epoch < minimum_release_age_seconds )); then
if [[ "${MISE_BIN_BYPASS_RELEASE_AGE:-}" == "1" ]]; then
echo "Bypassing mise release-age gate for $tag" >&2
else
continue
fi
fi
if [[ -z "$best_pkgver" ]] || [[ "$(vercmp "$pkgver" "$best_pkgver")" -gt 0 ]]; then
best_tag=$tag
best_pkgver=$pkgver
fi
done < <(jq -r '.[] | select((.draft or .prerelease) | not) | [.tag_name // empty, .published_at // empty] | @tsv' <<<"$releases")
if (( candidates == 0 )); then
echo "No stable mise releases found in the release feed" >&2
exit 1
fi
pkgver=${BASH_REMATCH[1]}
if [[ -z "$best_tag" ]]; then
echo "Every recent mise release is still inside the release-age quarantine; skipping" >&2
echo '{}'
exit 0
fi
tag=$best_tag
pkgver=$best_pkgver
checksums=$(curl -fsSL \
"https://github.com/$repo/releases/download/$tag/SHASUMS256.txt")