From 2c3629a0f2f82cd7dac8cd8e41e88b46a6d9561b Mon Sep 17 00:00:00 2001 From: HackingGate Date: Fri, 2 Oct 2026 01:32:29 +0900 Subject: [PATCH] Prepare uphold 1.24.0 One engine change since 1.23.0. supply-chain no longer hands an npm git dependency to guarddog, which asked npm for it and got a 404, so a repository depending on its own package by git exited 2 on every run. Each git dependency in a package.json's dependencies is held to the same first-party owner rule and git ls-remote check as a uv git source, against the commit bun.lock or package-lock.json records; a tag its # names must point at that commit. One with no recorded commit is refused by name, and guarddog reads the rest of the manifest (#290). A git remote spelled as an option (starting with -) is now refused for uv and npm alike, and git ls-remote takes the remote after --, so a manifest cannot hand git an --upload-pack command (#290). The tests assert every empty collection with a message that prints it, as Rust 1.99's clippy::assert_is_empty asks (#291). A consumer taking the pin to v1.24.0 needs no change. A repository whose package.json depends on a git source under another owner, or on one no lock pins, now fails the supply-chain section by name where it was could-not-look. --- Cargo.lock | 2 +- Cargo.toml | 2 +- README.md | 6 +++--- hooks/lefthook.yml | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 3cbb882..be79f62 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -719,7 +719,7 @@ dependencies = [ [[package]] name = "uphold" -version = "1.23.0" +version = "1.24.0" dependencies = [ "encoding_rs", "globset", diff --git a/Cargo.toml b/Cargo.toml index 11b9ebf..85c6d09 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "uphold" -version = "1.23.0" +version = "1.24.0" edition = "2024" # 1.90, and the floor is set by what the tree embeds rather than by taste: the # ripgrep stack -- globset 0.4.20 and ignore 0.4.33 in Cargo.lock -- refuses diff --git a/README.md b/README.md index b8e236d..6edce8e 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ When last counted, on 2026-09-23, 88 repositories carried an uphold policy, all of them maintained by one person and the coding agents working in them. ```sh -cargo install --git https://github.com/HackingGate/uphold --tag v1.23.0 +cargo install --git https://github.com/HackingGate/uphold --tag v1.24.0 ``` Or pin the pre-commit or lefthook manifest under [Install](#install). @@ -70,7 +70,7 @@ needed (`language: rust` bootstraps it). default_install_hook_types: [pre-commit, commit-msg, pre-merge-commit, pre-push] repos: - repo: https://github.com/HackingGate/uphold - rev: v1.23.0 + rev: v1.24.0 hooks: - id: uphold-check # the claims still hold - id: uphold-scan # the content policy @@ -125,7 +125,7 @@ bootstrapping a language, so the binary must be on PATH, from the # lefthook.yml remotes: - git_url: https://github.com/HackingGate/uphold - ref: v1.23.0 + ref: v1.24.0 configs: - hooks/lefthook.yml ``` diff --git a/hooks/lefthook.yml b/hooks/lefthook.yml index 525e771..9146cee 100644 --- a/hooks/lefthook.yml +++ b/hooks/lefthook.yml @@ -10,7 +10,7 @@ # # lefthook.yml, in the consuming repository # remotes: # - git_url: https://github.com/HackingGate/uphold -# ref: v1.23.0 +# ref: v1.24.0 # configs: # - hooks/lefthook.yml #