Dashboard › cli › Distillation
1830f144-027e-4df3-969a-ebcadf9ce25f["lore_tm_v1_wgaPu1AzYcstc9HmtNzK78WmAPFBRm0Pioux5cjcaDw","lore_tm_v1_ZI2Lm6yEkBucp2xzdIW04evMssJvevu3htHyu6ec_8E","lore_tm_v1_u4TN4Cfk_zFoz7q6rTx9uio5JEpmYT1t95rtYjjUBKs","lore_tm_v1_HxQob3LHwgWP95XdJeWmHLBJSOwvuyoUgJJkmWjCY4U","lore_tm_v1_UeLd3EzuAWsIVfk3d7YL__7dALVwOPbr66QDBwm4HEg","lore_tm_v1_9vzKMlBzoQYNX7-TvX_pnNo0c7jMqNaTVjs1zYfAtfw","lore_tm_v1_kv71FsQMiqJ1_ZJnLDvFobLUFrGFWR2L20L5m_2dq-s","lore_tm_v1_Rs0ksNTM94h3jCnIDYfVoNT4n283nMMrQyoa9YrVTQE","lore_tm_v1_8EGm2-9YyCn2Qivjik0qfH4zRqdL4j7SQy8-EaRyQdA","lore_tm_v1_T_0f3E2Nq2xGm3AL6VXDDTdbmd9nG_6mbwjmYSCKR3E","lore_tm_v1_j3whN-2kcYrXPwBw2lMnlJqnOnt96doYanWLKz58bbw","lore_tm_v1_RiGgEM5GqDrO6OpbLew6-IJO7r5kOmGYKHpQiqh8Me4","lore_tm_v1_jGoSi8YBCXeySSEVBbNUGMgy194iqAFzFZlMlFFta6A","lore_tm_v1_0LWre0z583F43yl0-Hq5VDlZYYAVRqbncptqpPdGYEg","lore_tm_v1_WzsuDjGGZU-vyZmh_K9JP-8eKZauoAAvtmyknCtkYVk","lore_tm_v1_TRVVOLSTFCrhwiCv14cwm_UnQ2SUDRNV2__4G-Do9M8","lore_tm_v1_nIDo1N8CJseYJwMkH1UnOKUP04jygdM0O5pAitMpi-c","lore_tm_v1_iiK2jnzzRmATMznE7bwy3j8JiCSAVDSYuzOlC2Nryf8","lore_tm_v1_K7vc6ByewSOq_teOvNhpSv-dYmY9yNheWYPw56nzomo","lore_tm_v1_8_Jp_Cl-I2pnIcvVhY6U_d5kUMyBJ1fK8IKT69rXNB8","lore_tm_v1_QraR8Wq6Juxph2YU5LEopXHzbfO0k0qW3X1s-k25ZiA","lore_tm_v1_BZcFvIdjRbNZrMfXGpebMkIxgLZmXmdJwesdm_OCZFE","lore_tm_v1_zdEnq9SsMAtAVsW6U8TTXu6tjQL9F8zliRaa6ENIo3A","lore_tm_v1_4EqIIQutJY60DHvQT5eKbhwrDa9L30H0k4bNn2K3JW4","lore_tm_v1_mHwtb5QWqoio4HVK0_gcRqOT_dln8_zS2YGGFNkSgmo","lore_tm_v1_rJkWVBpbslUGg8GW3MqZM-dwdhun6f75xPAuWcPmaO0","lore_tm_v1_kYsEx3_HwhoDS3G4QS96oYyXHG3fgQGSa0C5ZVTCgKQ","lore_tm_v1_GfcPuv5TWSK92BsyFt7h6lxmbq-zDVkQnzHkkpCCaoo","lore_tm_v1_LLiBjLlXK4c5lyVW5sc0GDq_LvkEhdllfE0fwo5ghs0"]
Date: Sep 10, 2026
MERGE verdicts from immutable correctness and security reviews, all CI/Warden gates green, and all review threads resolved before merging PR #1569; after merge, verify immutable commit parents and tree.878459c490576dbb7abb76d3a3dc1b5d9fc62c1f, replacement correctness task ses_f7672cd8dffeGBOabzuHhAYSqa, and security retry task ses_f76751b93ffesTYCzjjoYp3lpF.7d62ffa83 (fix(cli): preserve paginated request cancellation) was created with 2 files changed and 24 insertions, then pushed from 878459c49 to origin/feat/toolkit-bridge-upgrade.getsentry/cliβs default branch: 1 critical, 10 high, 10 moderate, and 1 low; details URL was https://github.com/getsentry/cli/security/dependabot.7d62ffa8317f9b98be0dc4afec0a927c1cabb0b7; the branch was clean after push.7d62ffa8317f9b98be0dc4afec0a927c1cabb0b7 and launched fresh correctness and security reviews against that exact revision.https://github.com/getsentry/cli/pull/1569 had base ec83887a16f780f32fba4b7d710bad262dba3a22, exact head 7d62ffa8317f9b98be0dc4afec0a927c1cabb0b7, and merge state BLOCKED.semgrep-cloud-platform/scan (queued) and Vercel β cli (pending).ses_f766b7f96ffeOX1iJTV9fAmbbR started and was subject to automatic notification onlyβno sleeping, polling, status requests, duplication, or overlapping work.u6pz6gl9 was scheduled for exact head 7d62ffa8317f9b98be0dc4afec0a927c1cabb0b7, correctness task ses_f766b7f96ffeOX1iJTV9fAmbbR, and security task ses_f766b435effeiR9auDk7bn6bqG; the merge gate remained substantive MERGE verdicts plus all gates, followed by immutable commit-parent/tree verification.ses_f7672cd8dffeGBOabzuHhAYSqa completed against prior head 878459c490576dbb7abb76d3a3dc1b5d9fc62c1f with DO-NOT-MERGE.packages/cli/src/lib/upgrade.ts:501-504: fetchLatestFromGitHubWithSource() accepted either an object or array for every source, allowing Toolkitβs release-list endpoint to accept malformed {tag_name:"cli@9.9.9"} and legacy /releases/latest to accept malformed [{tag_name:"9.9.9"}]; both could select and install 9.9.9.packages/cli/src/lib/upgrade.ts:797-803: explicit-source versionExists("curl", version, source) treated every successful HTTP response as existence proof without parsing tag_name, so an empty HTTP 200 returned true./latest responses must be one release object; explicit-source existence responses must parse and exactly compare tag_name with ${source.tagPrefix}${version}.{tag_name:"cli@9.9.9"} and must reject with no cache fallback or download; 2. Toolkit returns 404 and legacy /latest returns [{tag_name:"9.9.9"}], which must terminate in rejection; 3. versionExists(..., UPGRADE_SOURCES[0]) receives an empty HTTP 200 and must reject rather than return true.packages/cli/src/lib/binary.ts:500-514: fetchWithUpgradeError() preserved only errors named AbortError and did not inspect init.signal.aborted, affecting paginated GitHub discovery at packages/cli/src/lib/upgrade.ts:523-527.packages/cli/src/lib/ghcr.ts: isExternalAbort() at lines 79-96 required reason identity or an AbortError, so initial blob requests at lines 390-405 and redirect requests at lines 435-447 could replace an arbitrary caller reason when fetch rejected with another error shape.signal?.aborted and unconditionally throw signal.reason before transport classification."cancelled", reject fetch with TypeError("invalid_argument"), and assert the rejection is exactly "cancelled"; 2. repeat for both GHCR initial and redirected blob requests, asserting exact identity and one request per stage; 3. assert caller cancellation never triggers transport-cache fallback.packages/cli/src/commands/cli/upgrade.ts:221-235: only UpgradeTransportError permits automatic curl-cache fallback; HTTP failures, malformed successful responses, missing versions, and metadata errors remain terminal.packages/cli/src/lib/upgrade.ts:575-588,829-845: npm, pnpm, Bun, and Yarn pins undergo stable SemVer validation before registry access, rejecting malformed versions and semantic prereleases.packages/cli/src/lib/delta-upgrade.ts:75-120.741bd72559d1033c0f801cba98e635f85f0b96dcca6f2180f5d9158ffb5251fc, and passed git diff --check; it did not execute tests because worktree use would violate immutable-object-only review.7d62ffa83, but endpoint-shape validation and unconditional GHCR blob cancellation remained applicable to the new head./latest requires an object, and explicit-source stable existence reuses exact metadata validation rather than treating any HTTP 200 as proof.signal.reason before transport classification.packages/cli/src/lib/upgrade.ts and packages/cli/src/lib/ghcr.ts were updated with endpoint-specific/exact-tag metadata validation and stronger blob cancellation handling.packages/cli/test/lib/upgrade.test.ts included pagination-source rejection at line 287, Toolkit-404-to-legacy fallback at line 340, prefixed Toolkit tag probing/source retention at line 757, and no fallback from an explicit source at line 855.packages/cli/test/lib/upgrade.test.ts and packages/cli/test/lib/ghcr.test.ts were updated with endpoint-shape rejection, explicit-source exact metadata/empty-200 handling, and distinct-error/non-AbortError blob cancellation coverage.isExternalAbort() in src/lib/ghcr.ts:79, and undeclared variable parsePinnedGitHubRelease in src/lib/upgrade.ts:811; no fixes were automatically applied.packages/cli/src/lib/ghcr.ts was updated to remove the obsolete isExternalAbort() helper.packages/cli/src/lib/upgrade.ts was updated to extract and share the existing exact-tag response parser between ordered pinned resolution and explicit-source existence checks, ensuring identical fail-closed behavior.