Skip to content

chore(deps): update jdx/packslip action to v1.4.0 - #1508

Merged
jdx merged 1 commit into
mainfrom
chore/packslip-1.4.0
Sep 27, 2026
Merged

jdx merged 1 commit into
mainfrom
chore/packslip-1.4.0

Conversation

@jdx

@jdx jdx commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

https://entire.io/gh/jdx/usage/trails/54

Updates jdx/packslip to v1.4.0, pinned by SHA.

What changes for this release workflow:

  • Linux archives whose executables are fully static no longer get labelled libc: gnu when the file name does not say, so musl hosts such as Alpine can select them.
  • goreleaser-style 386, plain arm, and a few other architecture spellings are now recognized, and a Linux/BSD artifact whose architecture cannot be inferred is refused instead of being recorded as fitting every architecture. This release's current asset names all name an architecture, so nothing here should trip it.
  • packslip verify now reports the signing repository and owner IDs, which consumers use to follow renamed repositories safely.

AI-assisted — Tool: Claude Code; model: anthropic/claude-opus-5-5; version: unavailable.

🤖 Generated with Claude Code


Note

Low Risk
Single dependency pin in the release workflow; no application code or packslip configuration changes beyond the action version.

Overview
Bumps the jdx/packslip step in publish-cli from v1.2.0 to v1.4.0, still pinned by commit SHA. No workflow inputs or artifact patterns change—only the action version used when signing the release inventory after CLI builds land.

Consumers of that packslip indirectly get v1.4.0 behavior: more accurate libc labels for fully static Linux binaries (so musl hosts like Alpine can pick them), stricter architecture inference (unknown arch on Linux/BSD fails instead of matching everything), and packslip verify output that includes signing repository and owner IDs for safer tracking if repos are renamed.

Reviewed by Cursor Bugbot for commit 434a203. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Updated the CLI publishing process. The packaged binaries and resources remain unchanged, so this update does not change the CLI features or the contents users receive. No user-facing changes are included in this release.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: d08a4f2f-f123-4b08-a77e-d0b8ac3e90f6

📥 Commits

Reviewing files that changed from the base of the PR and between f3698cb and 434a203.

📒 Files selected for processing (1)
  • .github/workflows/publish-cli.yml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The CLI publishing workflow updates the packslip action from v1.2.0 to v1.4.0. Its configured artifacts, binary, and resources remain unchanged.

Changes

CLI publishing

Layer / File(s) Summary
Packslip action version
.github/workflows/publish-cli.yml
The workflow now references packslip v1.4.0 instead of v1.2.0. Configured artifacts, binary, and resources are unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 434a2

The Packslip update preserves the workflow’s existing artifact and resource behavior; no material merge risk is evident.

Architecture Summary

Architecture risk: 🔵 Low · up to 434a2

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/publish-cli.yml: The packslip action reference changes from v1.2.0 to v1.4.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the dependency update from jdx/packslip to v1.4.0, which is the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Updates a third-party GitHub Actions dependency.

The PR appears safe to merge based on the reviewed workflow change.

Summary

Updates the release workflow’s SHA-pinned jdx/packslip action from v1.2.0 to v1.4.0.

  • The workflow’s artifact patterns, action inputs, and release-job ordering remain unchanged.

Reviews (1) · Last reviewed commit: "chore(deps): update jdx/packslip action ..."

@jdx
jdx merged commit 2c22ae8 into main Sep 27, 2026
15 checks passed
@jdx
jdx deleted the chore/packslip-1.4.0 branch September 27, 2026 15:05
@github-actions

Copy link
Copy Markdown
Contributor

Instruction counts

benchmark trend instructions Δ wall (min) Δ
markdown ▁▁▁▁▂█▅▅ 285,874,362 → 285,847,287 -0.01% 49.65 → 49.76ms +0.22%
startup ▁▁▁▅▅▇▁█ 1,053,588 → 1,060,411 +0.65% 1.39 → 1.37ms -1.24%

No instruction-count regression above 1%.

Only instruction counts gate. Wall clock is shown for context — on identical hardware it moves 4-20% run to run.

Measured by tak — instruction-counted CLI benchmarks, stored in this repository's git notes.

Shadow comparison

Parsing mise use -g node@20 against a shadow of mise's committed spec.
Reported, not gated: the shadow grows as the derive learns to express more, so
what to watch is the ratio rather than either column.

framework stripped binary, bytes
usage 1262000
bpaf 2494656
clap 3100904
framework instructions, cold parse vs usage
usage 8530 —
clap 6314978 740x
bpaf 21909298 2568x
                                              min       p01       p10    median
usage-rs: argv -> struct                      798       799       802       827  ns
clap: build tree + parse -> struct        1234648   1240794   1252859   1268152  ns
bpaf: build parser + parse -> struct      3390555   3390555   3432736   3486943  ns

usage: argv -> struct                             774 ns      0.77 µs
clap: build tree + parse -> struct            1254364 ns   1254.36 µs
clap: parse -> struct, tree reused              49954 ns     49.95 µs
clap: build tree only                          747319 ns    747.32 µs

434a2032ea04 vs f3698cb31f89 · measured on the runner, not pushed to the history.

jdx pushed a commit that referenced this pull request Sep 28, 2026
<!-- entire-trail-link-start -->
https://entire.io/gh/jdx/usage/trails/33
<!-- entire-trail-link-end -->

### 🚀 Features

- **(cli)** publish a usage agent skill with packslip by
[@jdx](https://github.com/jdx) in
[#1509](#1509)
- **(complete)** complete a wrapped command's arguments with its own
shell completion via delegate= by [@jdx](https://github.com/jdx) in
[#1498](#1498)
- **(lib)** add getters that read FlagMeta, CommandMeta and ArgMeta
fields wherever they live by [@jdx](https://github.com/jdx) in
[#1491](#1491)
- **(lib)** export the chosen subcommand to scripts as usage_cmd by
[@jdx](https://github.com/jdx) in
[#1505](#1505)
- **(spec)** let a complete node sit inside the arg it completes by
[@jdx](https://github.com/jdx) in
[#1496](#1496)
- **(spec)** list an arg's possible values from a command with `choices
run=` by [@jdx](https://github.com/jdx) in
[#1497](#1497)

### 🐛 Bug Fixes

- **(bash)** complete `--flag=` values when the cursor sits after `=` by
[@jdx](https://github.com/jdx) in
[#1499](#1499)
- **(cli)** run scripts passed to usage bash through a pipe or process
substitution by [@jdx](https://github.com/jdx) in
[#1494](#1494)
- **(cli)** keep usage explain from running a spec's choices run=
commands by [@jdx](https://github.com/jdx) in
[#1503](#1503)
- **(complete)** read --line=LINE in completion requests from typed
completers by [@jdx](https://github.com/jdx) in
[#1487](#1487)
- **(complete)** show completion parse errors without garbling the
prompt by [@jdx](https://github.com/jdx) in
[#1495](#1495)
- **(derive)** ignore closed pipes instead of panicking in generated
parse() by [@jdx](https://github.com/jdx) in
[#1484](#1484)
- **(derive)** keep generated async dispatch from reserving stack for
every command by [@jdx](https://github.com/jdx) in
[#1488](#1488)
- **(fish)** complete words the user has started quoting by
[@jdx](https://github.com/jdx) in
[#1500](#1500)
- **(lib)** resolve inherited usage aliases after multiline workspace
entries by [@jdx](https://github.com/jdx) in
[#1507](#1507)
- **(lib)** make published usage-rs tests self-contained by
[@jdx](https://github.com/jdx) in
[#1510](#1510)
- **(zsh)** stop the completion-init handler from breaking file
completion for other commands by [@jdx](https://github.com/jdx) in
[#1493](#1493)

### 📚 Documentation

- **(cli)** describe fig output as the legacy Fig format by
[@jdx](https://github.com/jdx) in
[2a1bef6](2a1bef6)
- clarify CLI frameworks and generators on the homepage by
[@jdx](https://github.com/jdx) in
[#1482](#1482)

### 🛡️ Security

- remove Entire trail runners by [@jdx](https://github.com/jdx) in
[#1485](#1485)

### 🔍 Other Changes

- float jdx tools and aube on latest without a release-age delay by
[@jdx](https://github.com/jdx) in
[#1486](#1486)
- run cargo-semver-checks on every published crate by
[@jdx](https://github.com/jdx) in
[#1490](#1490)
- fail pull requests that grow the usage CLI or a derived CLI by more
than 1% by [@jdx](https://github.com/jdx) in
[#1492](#1492)
- make the binary-size check measure the pull request's own code by
[@jdx](https://github.com/jdx) in
[#1501](#1501)

### 📦️ Dependency Updates

- bump jdx/renovate-config workflows to c736149 by
[@jdx](https://github.com/jdx) in
[06f2f1b](06f2f1b)
- bump jdx/renovate-config workflows to aa49efc by
[@jdx](https://github.com/jdx) in
[9aaedef](9aaedef)
- bump jdx/renovate-config workflows to 5b46432 by
[@jdx](https://github.com/jdx) in
[36f8681](36f8681)
- pin jdx/renovate-config workflows to v1.0.0 by
[@jdx](https://github.com/jdx) in
[a31ae2f](a31ae2f)
- update communique to 1.4.2 in mise.lock by
[@jdx](https://github.com/jdx) in
[805396f](805396f)
- upgrade locked mise tools by [@jdx](https://github.com/jdx) in
[d8b761d](d8b761d)
- update jdx/packslip action to v1.4.0 by [@jdx](https://github.com/jdx)
in [#1508](#1508)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant