Dashboard › cli › Distillation
3e5c99a8-1b56-44d1-8bd0-ddbc3abc90f6["lore_tm_v1_rHxm9GpkfaxZYkDg-2YMrB4pbix-s9V2sgkZ3_1ozYM","lore_tm_v1_dXA-BY54FSMLxUQyZpj4KjJghDvY6g9a8lyjgM7G1Lw","lore_tm_v1_inmUwIOUEfoghHFEL7Lmm8hsGhJU0fKgPuzf7Wvfw-Y","lore_tm_v1_DIVjdqWwrKcjYi6OzU3UBuLQ1eh7lu8hZunrWVR3iuc","lore_tm_v1_K225venjRThUbkPdgrYXXNzR2-8Sw7obryKt0Tzyea8","lore_tm_v1_R6mqdpxEgUm9ezQGJT1fhWZGfae0cbyD7t7IoF6A_Uk","lore_tm_v1_a29Nt2hNwjlldgkTfedoJaSS-lSlK9pKP9hgrsFhBVM","lore_tm_v1_txpfWa8qrFxEc4qGd6axMz9Qmg-KNCVNoDxjYXGbP6Y","lore_tm_v1_EjhYlmdsLJs3U4J8n7o6WsAWl8NK-McYbKXWjKALfb8","lore_tm_v1_mSLcprpuxcYwDcvw8dtKwjF9VBX59wyajLF45_cVD0s","lore_tm_v1_sY_v-7cbQSTUwJAeyW9y2ZHSwsYfNr8s0xLbnE_3b6U","lore_tm_v1_OH_d3sqt7zdiDTDMM-gGkyPBs6BOSYLAMGuhdZGXAes","lore_tm_v1_jvMvaYGRc4jl1ghaQtTIUNa4O9PfHztzBk2OimZ8W28","lore_tm_v1_8_VrNXdtxbtWC947N0--GSeQhB2be-7iOXFChSEkVMg","lore_tm_v1_Fs0HYZES834EKRGF_BAUlTX6ED14UjVPwBXKFKYffi4","lore_tm_v1_VtoPjbZ9Chdh3_5YNoCyEHMSyV9a83vTtdMa-eKqw8I","lore_tm_v1_RsE94glTyLtk6ubvtto53QATjjyjhlAxl_KygXPywoM","lore_tm_v1_a5_fk3zO1qBZCQ_GlCxmcG-QIIymeJJwPplDdxa2bUc","lore_tm_v1_aT4IRK8Y0oZaOP1Qh2OqUt-BdSkNtgQIxEQ9aVv-TSM","lore_tm_v1_Zt-JYZSq0QuvMhrCYzEQtnzRPPgdJZl6O1plOHH6dxk","lore_tm_v1__qYXsdfxlgQF7UbPdvdP5YgcO5o5jVASOXG4PbG5Ckw","lore_tm_v1_8ETp8ZCNQivkhFtrFmas4kTlkWUAmeb1Ra1HBxvlhx8","lore_tm_v1_qiEJrujniL9RKFM4MIj92pHzbN_yKuGL5PYHniOIvF4","lore_tm_v1_RYbyDwQtRTen3qqfs6Ka9PHLy9V_AChFNsv-Q30jz4k","lore_tm_v1_B-q-6cVU3O9Ka9DDTaBRiWGOeeAYJAebVq6nIRXI6DI","lore_tm_v1_kHl6aDWMmDaFHKaLXcxfU4irkvgOj8-65q1Apqrs7XU","lore_tm_v1_UMS31q2QJrqt-FSjrjKeHGy5sJrudbJTca70uWZCM-M","lore_tm_v1_4_DhBNSJO4lX-3PC5sBOm-E2GXsHT941jpZjtW8kaPM","lore_tm_v1_mo7FPeTHR4N8g8qw6Adu1pOmydtrvwoTEamxq2UqXIc","lore_tm_v1_BPc46nKZcbNumHIdltfPiZAYc0ja5ByPde49ylRm6Os","lore_tm_v1_-jGglO0GsmNY-kV-4OVnzexKHzENgCLEZm-5q69QZz4","lore_tm_v1_KkPh_JuplvCpFyswDlxft-93abbpuK3BpCKDvMBsT4M","lore_tm_v1_ZiT6jWMRLdx05dj9Oy0fG_ih_hw3PU4n67v0dzu4iCE","lore_tm_v1_q-dThr8l8fLIyClR5VTZHynL17TAeGQ8EeFcOD4w5K0","lore_tm_v1_nnoiInOhYczh3UV_Nr9ftC1v3nsqfJYI3i6lEZDNU0E","lore_tm_v1_8Z0GJmalnuwDkOc7AJ4i84rTbJpXuoikB-E0NqqnTPw","lore_tm_v1_3NXt9xqBSMUA_qvWiHJf5hr5KoZBqz34YEQ9fqV-VVU","lore_tm_v1_q93gqPjrXQJvyTepio74Rdk7l6LkOybwhcYelEZtdCs","lore_tm_v1_mXlk7OqNKzIzdQYYyrgA1PpcYfOJQvWZ58p7C-U-mBY","lore_tm_v1_g7lcpVr_enqT6ytPliQhvfaOK3TKn2SvSq-A03L8zsU","lore_tm_v1_uz_zabsBbck8og-xcqk-L7mLN31_-Some0sySFzkBZw","lore_tm_v1_J0W17Ve_SM743u7TtRDQVDYG8bLgZPkVTxfWdotQq8M","lore_tm_v1_qHsdCBBaDe9njaS53W_3S7s5tImj8xqWPGhXLlJVqlc","lore_tm_v1_esbP-WqxSXn2uAWBL6HwB1qbUK9y8GBe_JzFCHYh1-E","lore_tm_v1_XE54x7UlTJXm1NqnZp1zICxperRFnpzSfj5xUKaAKdQ","lore_tm_v1_Oosid8Z1qAgnJiM72JXGtP03duz277-08xBBoPNTihc","lore_tm_v1_ccabd1LiDagGUMB-qxh5K7atSIRaXQzQUMVCvZwS1zc","lore_tm_v1_b88rUy7-7hqWaj7wp3nRmR7TmIxrI7el3x18qfdDxCk","lore_tm_v1_gmWagaO6_1OfStc0gv_bh-KqwxK1x6hfT2cT40pSUo8"]
Date: Sep 10, 2026
response.json() body-read sites: packages/cli/src/lib/upgrade.ts:509 (GitHub releases), packages/cli/src/lib/upgrade.ts:578 (npm latest version), packages/cli/src/lib/upgrade.ts:723 (release metadata), packages/cli/src/lib/ghcr.ts:234 (anonymous token), packages/cli/src/lib/ghcr.ts:277 (OCI manifest), and packages/cli/src/lib/ghcr.ts:492 (GHCR tags).parseUpgradeJson() handling in packages/cli/src/lib/binary.ts, replacing direct JSON reads in upgrade/GHCR paths, and adding runtime validation for OCI fields consumed downstream.packages/cli/src/lib/upgrade.ts failed because the expected older GitHub response cast did not match current lines 509-511; assistant confirmed the working tree was unchanged and switched to small call-site-specific patches.MERGE reports and all gates remained prerequisites to merge, followed by immutable merge-commit parent/tree verification.cea7b2afba91f11f1cdbb1785ea97ba61159520c and the actual security task as ses_f7665898bffevf1NoUXL04MCBb, rejecting a malformed task ID.MERGE verdict was received and recorded; security task ses_f7665898bffevf1NoUXL04MCBb still had to be awaited by notification only, with no polling or duplication.getUserAgent is imported from ./constants.js, not ./binary.js; current imports in packages/cli/src/lib/ghcr.ts:20-24 included PRIMARY_UPGRADE_SOURCE/UpgradeSource from ./binary.js, getUserAgent from ./constants.js, customFetch from ./custom-ca.js, and UpgradeError/UpgradeTransportError from ./errors.js.parseUpgradeJson alongside the existing binary-source import and splitting validator insertion from call-site edits.packages/cli/src/lib/ghcr.ts; assistant reported that GHCR token parsing now requires a non-empty string token and GHCR manifests are runtime-validated as complete OCI manifests before nightly source selection.test/lib/ghcr.test.ts and test/lib/upgrade.test.ts under Vitest v4.1.10 produced 214 tests: 207 passed and 7 failed across both files. Failures were 3 GHCR manifest tests and 4 upgrade/nightly tests, all rejecting abbreviated fixtures as Manifest for tag "..." returned invalid metadata.packages/cli/test/lib/ghcr.test.ts found 19 abbreviated digest references, including manifest values sha256:config, sha256:abc123, and sha256:def456, plus blob-path test values such as sha256:abc.packages/cli/test/lib/upgrade.test.ts found 7 schemaVersion: 2 manifest fixtures, including an inline layer digest sha256:blobdigest at line 2200.packages/cli/test/lib/ghcr.test.ts and packages/cli/test/lib/upgrade.test.ts.Response.prototype patch in the token body-cancellation regression with a per-response json override to avoid global coupling and keep the test isolated and deterministic.test/lib/upgrade.test.ts. The remaining failures were two nightly-channel tests and one mismatched-nightly-annotation test whose inline fixtures supplied annotations without required schemaVersion and layers.packages/cli/test/lib/upgrade.test.ts to complete OCI manifests with schemaVersion: 2 and empty layers, preserving version annotations 0.0.0-dev.1740393600 and mismatch semantics between requested 0.14.0-dev.123 and returned 0.14.0-dev.124.test/lib/ghcr.test.ts and test/lib/upgrade.test.ts suites passed completely: 222/222 tests across 2 files.packages/cli/test/commands/cli/upgrade.test.ts, intended to prove that a fetch which returns headers but terminates during body consumption is classified as transport failure rather than malformed metadata.test/commands/cli/upgrade.test.ts. Failures covered: 1. 'nightly' positional channel, 2. persisted nightly channel, 3. valid nightly target in --check, 4. newer-nightly upgrade hint, 5. npm-to-standalone migration for pinned nightly, and 6. pinned nightly allowed for Homebrew.mockNightlyVersion() in packages/cli/test/commands/cli/upgrade.test.ts:254-276, rather than production behavior.mockNightlyVersion(version: string) was updated so its /manifests/nightly response models a complete empty-layer OCI manifest instead of only { annotations: { version } }; its GHCR token exchange continues returning non-empty string token "test-token".mockNightlyVersion().packages/cli/test/commands/cli/upgrade.test.ts:1208-1287 as an incomplete manifest containing version 0.99.0-dev.1234567890, layer digest sha256:abc456, and filename annotation selected by platform; the related mocked blob redirect was /blobs/sha256:abc456 β https://blob.example.com/nightly.gz.schemaVersion: 2, a 64-hex digest, media type, and non-negative size, and updated its blob URL assertion accordingly; the check-only Homebrew fixture for nightly-0.99.0-dev.1234567890 received complete empty-layer OCI fields.