From ca517f7759f20584c7fee1c5679653259bac1742 Mon Sep 17 00:00:00 2001 From: Julian Grinblat Date: Thu, 24 Sep 2026 03:18:30 +0900 Subject: [PATCH 1/4] feat(deps): allow ignoring known-broken upstream releases check_upstream_version now skips a dep's latest release if it's listed in .external_versions/.ignore, so the update workflow stops re-proposing a version known to be broken until upstream ships a newer one. Co-Authored-By: Claude Sonnet 5 --- .external_versions/coursier.ignore | 4 ++++ utils/check_upstream_version | 5 +++++ 2 files changed, 9 insertions(+) create mode 100644 .external_versions/coursier.ignore diff --git a/.external_versions/coursier.ignore b/.external_versions/coursier.ignore new file mode 100644 index 0000000000..b31ac9ffc6 --- /dev/null +++ b/.external_versions/coursier.ignore @@ -0,0 +1,4 @@ +# v2.1.25: standalone launcher jar is broken, bundles a mismatched cats lib - +# every command fails with NoSuchMethodError during arg parsing. +# https://github.com/coursier/coursier/issues/3865 +v2.1.25 diff --git a/utils/check_upstream_version b/utils/check_upstream_version index c56bfda865..5824de67a5 100755 --- a/utils/check_upstream_version +++ b/utils/check_upstream_version @@ -5,6 +5,7 @@ DEP="$1" SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" 2>/dev/null && pwd) VERSION_FILE="$SCRIPT_DIR/../.external_versions/$DEP" +IGNORE_FILE="$SCRIPT_DIR/../.external_versions/$DEP.ignore" github_repo() { case "$1" in @@ -34,6 +35,10 @@ LATEST="$( CURRENT="$(cat "$VERSION_FILE")" +if [ -f "$IGNORE_FILE" ] && grep -qxF "$LATEST" "$IGNORE_FILE"; then + exit 0 +fi + if [ "$LATEST" != "$CURRENT" ]; then printf '%s\n' "$LATEST" fi From 9d501df3885f3e2beef63b5ef5d9abc66b11f9ae Mon Sep 17 00:00:00 2001 From: Julian Grinblat Date: Thu, 24 Sep 2026 03:27:43 +0900 Subject: [PATCH 2/4] feat(deps): query PR history instead of a repo file to skip rejected versions Replace the .external_versions/.ignore file approach with a lookup against GitHub's own PR history: closing a rejected version's update PR with the "wontfix" label is enough for check_upstream_version to recognize it later, since the closed PR's head branch name (which GitHub keeps even after the branch is deleted) encodes dep + version. No repo state to commit or keep in sync. Co-Authored-By: Claude Sonnet 5 --- .external_versions/coursier.ignore | 4 ---- .github/workflows/update_deps.yml | 2 ++ utils/check_upstream_version | 33 ++++++++++++++++++++++++------ 3 files changed, 29 insertions(+), 10 deletions(-) delete mode 100644 .external_versions/coursier.ignore diff --git a/.external_versions/coursier.ignore b/.external_versions/coursier.ignore deleted file mode 100644 index b31ac9ffc6..0000000000 --- a/.external_versions/coursier.ignore +++ /dev/null @@ -1,4 +0,0 @@ -# v2.1.25: standalone launcher jar is broken, bundles a mismatched cats lib - -# every command fails with NoSuchMethodError during arg parsing. -# https://github.com/coursier/coursier/issues/3865 -v2.1.25 diff --git a/.github/workflows/update_deps.yml b/.github/workflows/update_deps.yml index 6ceeaf319e..2f05c57b56 100644 --- a/.github/workflows/update_deps.yml +++ b/.github/workflows/update_deps.yml @@ -32,6 +32,8 @@ jobs: - name: Check for update id: check + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | new_version="$(utils/check_upstream_version "${{ matrix.dep }}")" if [[ -n "$new_version" ]]; then diff --git a/utils/check_upstream_version b/utils/check_upstream_version index 5824de67a5..e3d91bbf2f 100755 --- a/utils/check_upstream_version +++ b/utils/check_upstream_version @@ -5,7 +5,6 @@ DEP="$1" SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" 2>/dev/null && pwd) VERSION_FILE="$SCRIPT_DIR/../.external_versions/$DEP" -IGNORE_FILE="$SCRIPT_DIR/../.external_versions/$DEP.ignore" github_repo() { case "$1" in @@ -21,6 +20,32 @@ github_repo() { esac } +# A version we've deliberately rejected (e.g. a broken upstream release) gets +# its update PR closed with the "wontfix" label instead of merged. Checking +# for that PR - by its branch name, which GitHub keeps even after the branch +# itself is deleted - lets us skip re-proposing it without committing +# anything to the repo. +was_rejected() { + dep="$1" + version="$2" + + own_repo="${GITHUB_REPOSITORY:-}" + if [ -z "$own_repo" ]; then + own_repo="$( + git -C "$SCRIPT_DIR" remote get-url origin 2>/dev/null \ + | sed -E 's#^[a-zA-Z]+://##; s#^[^@]*@##; s#^[^:/]+[:/]##; s#\.git$##' + )" + fi + [ -n "$own_repo" ] || return 1 + + set -- -fsSL "https://api.github.com/repos/$own_repo/pulls?head=${own_repo%%/*}:update/$dep/$version&state=closed" + if [ -n "${GITHUB_TOKEN:-}" ]; then + set -- "$@" -H "Authorization: Bearer $GITHUB_TOKEN" + fi + + curl "$@" | jq -e 'any(.[]; .labels[].name == "wontfix")' >/dev/null 2>&1 +} + if [ ! -f "$VERSION_FILE" ]; then echo "Missing version file for $DEP" >&2 exit 1 @@ -35,10 +60,6 @@ LATEST="$( CURRENT="$(cat "$VERSION_FILE")" -if [ -f "$IGNORE_FILE" ] && grep -qxF "$LATEST" "$IGNORE_FILE"; then - exit 0 -fi - -if [ "$LATEST" != "$CURRENT" ]; then +if [ "$LATEST" != "$CURRENT" ] && ! was_rejected "$DEP" "$LATEST"; then printf '%s\n' "$LATEST" fi From 16f766ef7de0fc9b35f84bfde4d90c12845a37f3 Mon Sep 17 00:00:00 2001 From: Julian Grinblat Date: Thu, 24 Sep 2026 04:06:20 +0900 Subject: [PATCH 3/4] refactor(deps): use gh pr list instead of hand-rolled curl+jq gh already does head-branch + label filtering server-side, and reads GITHUB_TOKEN for auth automatically - no need to derive owner/repo from the git remote URL by hand or build the API request manually. Co-Authored-By: Claude Sonnet 5 --- utils/check_upstream_version | 17 ++--------------- 1 file changed, 2 insertions(+), 15 deletions(-) diff --git a/utils/check_upstream_version b/utils/check_upstream_version index e3d91bbf2f..8717084122 100755 --- a/utils/check_upstream_version +++ b/utils/check_upstream_version @@ -29,21 +29,8 @@ was_rejected() { dep="$1" version="$2" - own_repo="${GITHUB_REPOSITORY:-}" - if [ -z "$own_repo" ]; then - own_repo="$( - git -C "$SCRIPT_DIR" remote get-url origin 2>/dev/null \ - | sed -E 's#^[a-zA-Z]+://##; s#^[^@]*@##; s#^[^:/]+[:/]##; s#\.git$##' - )" - fi - [ -n "$own_repo" ] || return 1 - - set -- -fsSL "https://api.github.com/repos/$own_repo/pulls?head=${own_repo%%/*}:update/$dep/$version&state=closed" - if [ -n "${GITHUB_TOKEN:-}" ]; then - set -- "$@" -H "Authorization: Bearer $GITHUB_TOKEN" - fi - - curl "$@" | jq -e 'any(.[]; .labels[].name == "wontfix")' >/dev/null 2>&1 + count="$(gh pr list --state closed --head "update/$dep/$version" --label wontfix --json number --jq 'length' 2>/dev/null)" || return 1 + [ "${count:-0}" -gt 0 ] } if [ ! -f "$VERSION_FILE" ]; then From c185f91bf792af822b6c212d6599453cd04019ba Mon Sep 17 00:00:00 2001 From: Julian Grinblat Date: Thu, 24 Sep 2026 04:07:43 +0900 Subject: [PATCH 4/4] refactor(deps): use gh api for the upstream release lookup too Same rationale as the PR-history check: gh already handles auth and request building. Drops the last curl+jq usage, so the separate "Install jq" step in the workflow is dead weight - removed. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/update_deps.yml | 5 ----- utils/check_upstream_version | 5 +---- 2 files changed, 1 insertion(+), 9 deletions(-) diff --git a/.github/workflows/update_deps.yml b/.github/workflows/update_deps.yml index 2f05c57b56..e605219c01 100644 --- a/.github/workflows/update_deps.yml +++ b/.github/workflows/update_deps.yml @@ -25,11 +25,6 @@ jobs: steps: - uses: actions/checkout@v7 - - name: Install jq - uses: awalsh128/cache-apt-pkgs-action@latest - with: - packages: jq - - name: Check for update id: check env: diff --git a/utils/check_upstream_version b/utils/check_upstream_version index 8717084122..df9266ea4d 100755 --- a/utils/check_upstream_version +++ b/utils/check_upstream_version @@ -40,10 +40,7 @@ fi REPO="$(github_repo "$DEP")" -LATEST="$( - curl -fsSL "https://api.github.com/repos/$REPO/releases/latest" \ - | jq -r '.tag_name' -)" +LATEST="$(gh api "repos/$REPO/releases/latest" --jq '.tag_name')" CURRENT="$(cat "$VERSION_FILE")"