Skip to content

pluto: update checksum for 5.24.0.release#289553

Merged
BrewTestBot merged 1 commit into
mainfrom
pluto-update-checksum-for-5.24.0.release
Jun 26, 2026
Merged

pluto: update checksum for 5.24.0.release#289553
BrewTestBot merged 1 commit into
mainfrom
pluto-update-checksum-for-5.24.0.release

Conversation

@stefanb

@stefanb stefanb commented Jun 24, 2026

Copy link
Copy Markdown
Member

Github actions log https://github.com/FairwindsOps/pluto/actions/workflows/github-action-test.yml
image
indicates that the tag v5.24.0 was present on at least 2 commits:

Diff FairwindsOps/pluto@c85f54c...dd5ec8c shows just goreleaser config changes.

Ref:


  • Have you followed the guidelines for contributing?
  • Have you ensured that your commits follow the commit style guide?
  • Have you checked that there aren't other open pull requests for the same formula update/change?
  • Have you built your formula locally with HOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>?
  • Is your test running fine brew test <formula>?
  • Does your build pass brew audit --strict <formula> (after doing HOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>)? If this is a new formula, does it pass brew audit --new <formula>?

  • AI was used to generate or assist with generating this PR. Please specify below how you used AI to help you, and what steps you have taken to manually verify the changes.

@stefanb stefanb added checksum mismatch SHA-256 doesn't match the download CI-no-bottles Merge without publishing bottles CI-checksum-change-confirmed A checksum change was confirmed by upstream labels Jun 24, 2026
@github-actions github-actions Bot added the go Go use is a significant feature of the PR or issue label Jun 24, 2026
@stefanb stefanb added the ready to merge PR can be merged once CI is green label Jun 24, 2026
@SMillerDev

Copy link
Copy Markdown
Member

Doesn't explain why they retagged though

@stefanb

stefanb commented Jun 24, 2026

Copy link
Copy Markdown
Member Author

Doesn't explain why they retagged though

Diff FairwindsOps/pluto@c85f54c...dd5ec8c explains it: to adjust goreleaser config to fix the

  • release signatures and
  • signature verification instructions in the generated release notes footer

not enough? It seems understandable that they wanted to quickly adjust the existing release instead of properly tagging a new one.

@SMillerDev

Copy link
Copy Markdown
Member

Who says it was actually them that changed the signing settings? Homebrew's policy is to treat changing tags as an upstream security issue unless confirmed otherwise by upstream. Just because we can assume it was intentional does not make it benign.

@stefanb stefanb added upstream issue An upstream issue report is needed and removed ready to merge PR can be merged once CI is green labels Jun 24, 2026
@stefanb

stefanb commented Jun 25, 2026

Copy link
Copy Markdown
Member Author

Retagging confirmed upstream in

@BrewTestBot
BrewTestBot added this pull request to the merge queue Jun 26, 2026
Merged via the queue into main with commit 64d3a3b Jun 26, 2026
45 checks passed
@BrewTestBot
BrewTestBot deleted the pluto-update-checksum-for-5.24.0.release branch June 26, 2026 01:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

checksum mismatch SHA-256 doesn't match the download CI-checksum-change-confirmed A checksum change was confirmed by upstream CI-no-bottles Merge without publishing bottles go Go use is a significant feature of the PR or issue upstream issue An upstream issue report is needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants