Skip to content

Review held plugin: xpufx/updates #124

Description

@boudra

xpufx/updates remains held at @xpufx/paseo-plugin-updates@0.1.4 for version/stamp differences from its self-declared source revision.

The published artifact declares PLUGIN_VERSION = "0.1.4+d7d86ff9" in shared/version.ts:2. That short hash resolves to repository commit d7d86ff93b960edf285173f74fbd5df867d09653, under plugins/plugin-updates. This is a self-declared version stamp; npm provides no gitHead or attested publication commit for this version.

The four helper import rewrites are explained by scripts/publish-npm.mjs:245-281; the shipped vendor files are byte-identical to those committed at that revision. These are publishing transformations, not runtime logic drift. The user-triggered update path clears under the new confirmation rule: checking for updates does not pull or reload software.

The earlier comparison to an unrelated available tag did not establish a mismatch and is not used for this decision. The version/stamp differences above remain held under the maintainer's source-match ruling; no maliciousness is alleged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions