xpufx/updates remains held at @xpufx/paseo-plugin-updates@0.1.4 for version/stamp differences from its self-declared source revision.
The published artifact declares PLUGIN_VERSION = "0.1.4+d7d86ff9" in shared/version.ts:2. That short hash resolves to repository commit d7d86ff93b960edf285173f74fbd5df867d09653, under plugins/plugin-updates. This is a self-declared version stamp; npm provides no gitHead or attested publication commit for this version.
The four helper import rewrites are explained by scripts/publish-npm.mjs:245-281; the shipped vendor files are byte-identical to those committed at that revision. These are publishing transformations, not runtime logic drift. The user-triggered update path clears under the new confirmation rule: checking for updates does not pull or reload software.
The earlier comparison to an unrelated available tag did not establish a mismatch and is not used for this decision. The version/stamp differences above remain held under the maintainer's source-match ruling; no maliciousness is alleged.
xpufx/updatesremains held at@xpufx/paseo-plugin-updates@0.1.4for version/stamp differences from its self-declared source revision.The published artifact declares
PLUGIN_VERSION = "0.1.4+d7d86ff9"inshared/version.ts:2. That short hash resolves to repository commitd7d86ff93b960edf285173f74fbd5df867d09653, underplugins/plugin-updates. This is a self-declared version stamp; npm provides no gitHead or attested publication commit for this version.package.json:5says0.1.4, while the stamped source's package.json:5 says0.1.3.shared/version.ts:2says0.1.4+d7d86ff9, while the stamped source's shared/version.ts:2 says0.1.3+bbd70d03.The four helper import rewrites are explained by scripts/publish-npm.mjs:245-281; the shipped vendor files are byte-identical to those committed at that revision. These are publishing transformations, not runtime logic drift. The user-triggered update path clears under the new confirmation rule: checking for updates does not pull or reload software.
The earlier comparison to an unrelated available tag did not establish a mismatch and is not used for this decision. The version/stamp differences above remain held under the maintainer's source-match ruling; no maliciousness is alleged.