From eca3ce78159d0ba81625d3993453be914d6feb91 Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Mon, 24 Aug 2026 14:21:41 -0400 Subject: [PATCH] mise-bin: ship the newest release that has cleared the 24h quarantine Gating on /releases/latest alone starves updates when mise's near-daily cadence keeps the newest release perpetually inside the quarantine window: today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past 24 hours. Walk the release list (drafts and prereleases excluded) and pick the newest release, by vercmp, whose published_at is at least 24 hours old. The quarantine guarantee is unchanged: nothing younger than the window ever ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid tags or timestamps still fail closed - now for every release in the feed, plus a hard failure if the feed reports no stable releases at all. --- pkgbuilds/mise-bin/.omarchy/upstream.sh | 69 +++++++++++++++++-------- 1 file changed, 48 insertions(+), 21 deletions(-) diff --git a/pkgbuilds/mise-bin/.omarchy/upstream.sh b/pkgbuilds/mise-bin/.omarchy/upstream.sh index 365063d..cad158a 100644 --- a/pkgbuilds/mise-bin/.omarchy/upstream.sh +++ b/pkgbuilds/mise-bin/.omarchy/upstream.sh @@ -2,34 +2,61 @@ set -euo pipefail repo="jdx/mise" -release=$(curl -fsSL "https://api.github.com/repos/$repo/releases/latest") -tag=$(jq -r '.tag_name // empty' <<<"$release") -published_at=$(jq -r '.published_at // empty' <<<"$release") - -if [[ ! "$tag" =~ ^v([A-Za-z0-9._+]+)$ ]]; then - echo "Latest mise release has an invalid tag: ${tag:-}" >&2 - exit 1 -fi - -if [[ -z "$published_at" ]] || ! published_epoch=$(date --date="$published_at" +%s); then - echo "Latest mise release has an invalid published_at: ${published_at:-}" >&2 - exit 1 -fi # Keep a compromised mise release from reaching Omarchy before there has been -# a full day for maintainers and the community to notice and pull it. +# a full day for maintainers and the community to notice and pull it. Walking +# the release list instead of gating on /releases/latest alone means mise's +# near-daily cadence cannot starve updates: the newest release that has +# finished its quarantine ships even while an even newer one is still inside +# it. Nothing younger than the window ever ships without the explicit bypass. minimum_release_age_seconds=$((24 * 60 * 60)) now=$(date +%s) -if (( now - published_epoch < minimum_release_age_seconds )); then - if [[ "${MISE_BIN_BYPASS_RELEASE_AGE:-}" == "1" ]]; then - echo "Bypassing mise release-age gate for $tag" >&2 - else - echo '{}' - exit 0 + +releases=$(curl -fsSL "https://api.github.com/repos/$repo/releases?per_page=20") + +candidates=0 +best_tag="" +best_pkgver="" +while IFS=$'\t' read -r tag published_at; do + if [[ ! "$tag" =~ ^v([A-Za-z0-9._+]+)$ ]]; then + echo "mise release has an invalid tag: ${tag:-}" >&2 + exit 1 fi + pkgver=${BASH_REMATCH[1]} + + if [[ -z "$published_at" ]] || ! published_epoch=$(date --date="$published_at" +%s); then + echo "mise release $tag has an invalid published_at: ${published_at:-}" >&2 + exit 1 + fi + candidates=$((candidates + 1)) + + if (( now - published_epoch < minimum_release_age_seconds )); then + if [[ "${MISE_BIN_BYPASS_RELEASE_AGE:-}" == "1" ]]; then + echo "Bypassing mise release-age gate for $tag" >&2 + else + continue + fi + fi + + if [[ -z "$best_pkgver" ]] || [[ "$(vercmp "$pkgver" "$best_pkgver")" -gt 0 ]]; then + best_tag=$tag + best_pkgver=$pkgver + fi +done < <(jq -r '.[] | select((.draft or .prerelease) | not) | [.tag_name // empty, .published_at // empty] | @tsv' <<<"$releases") + +if (( candidates == 0 )); then + echo "No stable mise releases found in the release feed" >&2 + exit 1 fi -pkgver=${BASH_REMATCH[1]} +if [[ -z "$best_tag" ]]; then + echo "Every recent mise release is still inside the release-age quarantine; skipping" >&2 + echo '{}' + exit 0 +fi + +tag=$best_tag +pkgver=$best_pkgver checksums=$(curl -fsSL \ "https://github.com/$repo/releases/download/$tag/SHASUMS256.txt")