Skip to content

Sync the reference formula to the published 0.14.0 tap - #41

Merged
Zenofex merged 1 commit into
mainfrom
sync-formula-0.14.0
Oct 8, 2026
Merged

Zenofex merged 1 commit into
mainfrom
sync-formula-0.14.0

Conversation

@Zenofex

@Zenofex Zenofex commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

BootIntel/homebrew-tap is now at 0.14.0 (1b7beba), so this copy was claiming four checksums that no longer correspond to what brew install fetches. The file's own header makes the case: a stale copy of a formula is worse than no copy, because it invites someone to trust the checksums in it.

The body is taken verbatim from the live tap rather than edited in place, and asserted byte-identical to it apart from this repo's header — the invariant that header asks for, so a diff between the two is a real finding rather than noise.

How the digests were obtained

Per docs/releasing.md step 7, read out of the release's own SHA256SUMS rather than transcribed, then paired to platforms by matching each url line rather than assuming the order of the four blocks. Then verified the way that matters: all four assets downloaded from the exact URLs the formula uses and hashed.

OK    aarch64-macos
OK    x86_64-macos
OK    aarch64-linux
OK    x86_64-linux

A wrong digest makes brew install fail with a checksum mismatch, which reads to a user like a compromised download.

🤖 Generated with Claude Code

BootIntel/homebrew-tap is at 0.14.0 (commit 1b7beba), so this copy was claiming
four checksums that no longer correspond to what `brew install` fetches. The
file's own header makes the case: a stale copy of a formula is worse than no
copy, because it invites someone to trust the checksums in it.

Body taken verbatim from the live tap rather than edited in place, and asserted
byte-identical to it apart from this repo's header, which is the invariant the
header asks for so a diff between the two is a real finding rather than noise.

The four digests were read out of the release's SHA256SUMS, paired to platforms
by matching each url line rather than assuming block order, and then verified
by downloading all four assets from the URLs the formula actually uses and
hashing them. All four matched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit cbc32aa into main Oct 8, 2026
11 checks passed
@Zenofex
Zenofex deleted the sync-formula-0.14.0 branch October 8, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant