Repository navigation
chore(deps): update devbox packages across all projects - #2974
Conversation
Run `devbox update` across every devbox.json in the repo, followed by `devbox update --sync-lock` to reconcile shared lock entries. 59 distinct package bumps across 52 devbox.lock files, including: - go 1.26.3 -> 1.27.0, git 2.54.0 -> 2.55.0, fd 10.4.2 -> 10.5.0 - nodejs 25.8.1 -> 26.8.1, nodejs-slim 26.7.0 -> 26.8.1, bun 1.0.33 -> 1.3.13 - python 3.12.1 -> 3.14.4, poetry 1.7.1 -> 2.4.1, pipenv 2023.2.4 -> 2026.5.1 - php 8.3.3 -> 8.5.9, ruby 4.0.2 -> 4.0.6, rustup 1.26.0 -> 1.29.0 - postgresql 17.5 -> 18.6, redis 7.2.4 -> 8.10.1, valkey 7.2.5 -> 9.1.1, mariadb 11.0.4 -> 11.8.8, mysql80 8.0.36 -> 8.0.45 - nginx 1.24.0 -> 1.30.4, caddy 2.7.6 -> 2.11.4, apache 2.4.58 -> 2.4.68 - ghc 9.4.8 -> 9.10.3, stack 2.13.1 -> 3.9.3, dotnet-sdk 6.0.418 -> 8.0.424 Only devbox.lock files change; no devbox.json is modified. Unversioned "nixpkg"-source entries are left alone, which is what `devbox update` does for them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015RaccMofrSPEL7v8RzpoWb
The go@latest bump to 1.27.0 broke `devbox run lint`: nix/flake/flakeref_test.go:63:1: File is not properly formatted (gofmt) Go 1.27's gofmt changed the alignment heuristic for composite literals, so a file correctly formatted for the repo's pinned toolchain is reported as unformatted. The same run also panicked five staticcheck analyzers (buildir, typedness, nilness, fact_purity, SA5012) with "unexpected expr: *ast.KeyValueExpr" while building IR from Go 1.27 syntax. Both come from golangci-lint v1.64.8, which go.mod pins as a tool and which predates Go 1.27. go.mod also declares `go 1.26.1`, so reformatting the test file for the newer gofmt would break lint for anyone on the pinned toolchain, and would leave the analyzer panics (and the lost coverage) in place. Upgrading golangci-lint is out of scope for a lockfile refresh, so pin go back to 1.26.3 and leave the rest of the update in place. fd, git and nodejs-slim keep their bumps in this lockfile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015RaccMofrSPEL7v8RzpoWb
|
Two symptoms, one cause:
Both come from So Verified locally against the pinned toolchain before pushing: Bumping Generated by Claude Code |
Four are upstream problems with the new package, so the package goes back
and the rest of that lockfile keeps its bumps:
- dotnet-sdk 8.0.424 -> 6.0.418 (csharp, fsharp). The 8.0.424 build's
libhostfxr.so resolves against the runner's system glibc and needs
GLIBC_ABI_GNU2_TLS, which it does not export:
Failed to load .../host/fxr/8.0.30/libhostfxr.so, error:
/lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_ABI_GNU2_TLS' not found
- jdk@19 19-ga -> 19.0.2+7 (java/gradle, java/maven). Newer nixpkgs marks
the rebased package insecure and refuses to evaluate it:
error: Package 'openjdk-19-ga' ... is marked as insecure, refusing to evaluate
gradle 8.14.4 and maven 3.9.16 are unaffected and stay.
Two are this repo's to fix, so the bump stays and the example is corrected:
- poetry-pyproject-subdir: Poetry 2.x makes "no file/folder found for
package poetry-pyproject-subdir-service" a hard error where 1.7 only
warned. This example uses Poetry for dependency management only and has
no service/ package, so declare package-mode = false, which is what
Poetry's own error recommends. poetry-demo has a real package directory
and already passes on 2.4.1.
- stacks/rails: the Gemfile pinned ruby "4.0.2" exactly, so ruby 4.0.6
failed with "Your Ruby version is 4.0.6, but your Gemfile specified
4.0.2". Move the pin and Gemfile.lock's RUBY VERSION to 4.0.6.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015RaccMofrSPEL7v8RzpoWb
|
The example matrix on 773d8be surfaced six failures across the three Reverted — the new package is broken upstream, nothing this repo can fix:
Only those two packages went back. Worth noting for a follow-up: Fixed — the bump was fine, the example needed updating:
One caveat on that last one: I wrote Also confirmed green on 773d8be: Generated by Claude Code |
Review flagged platform blocks disappearing from the `systems` maps. Two of them are real regressions rather than routine churn, because the newer version has no macOS build in the devbox-search index at all: - stack 2.13.1 -> 3.9.3 dropped aarch64-darwin, i.e. Apple Silicon - libffi 3.4.4 -> 3.8.0 dropped both darwin systems, breaking the jekyll example on every Mac Upstream confirms the versions, not the run, are the cause: /v2/resolve?name=stack&version=3.9.3 -> aarch64-linux, x86_64-darwin, x86_64-linux /v2/resolve?name=libffi&version=3.8.0 -> aarch64-linux, x86_64-linux /v2/resolve?name=libffi&version=3.4.4 -> all four Pinning both back keeps the older resolution, which still carries every platform. The remaining 30 dropped blocks are all x86_64-darwin on packages whose new versions no longer publish an Intel-mac build (redis, postgresql, mysql, valkey, python, nginx, php, fd, git and others). That is inherent to taking the upgrade, not something a re-run can restore, so those stay and are called out in the PR description instead. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015RaccMofrSPEL7v8RzpoWb
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance (no CLAUDE.md files exist in this repo).
🤖 Generated with Claude Code |
## Summary Fixes the nightly `cli-tests` failure in `stacks_jekyll_run_test` on macOS (e.g. run 35838473204), failing every scheduled run since #2974. That PR bumped `ruby@3.1` to 3.1.7 (`nixpkgs/bce5fe2b#ruby_3_1`), whose aarch64-darwin build lacks the `socket` extension, so `gem install` fails with `uninitialized constant Gem::Commands::InstallCommand` (masking `LoadError: cannot load such file -- socket`). This restores the previous 3.1.4 lock entry, same as #2974 did for `libffi` and `stack`; #2974's own CI missed it because macOS only runs on schedule or with `run-mac-tests`. ## How was it tested? Locally on arm64 macOS: `DEVBOX_RUN_PROJECT_TESTS=1 go test ./testscripts -run TestExamples/stacks_jekyll_run_test` passes with this change and fails with the same error on the current `main` lockfile. ## Community Contribution License All community contributions in this pull request are licensed to the project maintainers under the terms of the [Apache 2 License](https://www.apache.org/licenses/LICENSE-2.0). By creating this pull request, I represent that I have the right to license the contributions to the project maintainers under the Apache 2 License as stated in the [Community Contribution License](https://github.com/jetify-com/opensource/blob/main/CONTRIBUTING.md#community-contribution-license). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Summary
Refreshes the pinned package versions in every
devbox.jsonproject in the repo, then reconciles shared entries withdevbox update --sync-lock.52
devbox.lockfiles changed. Of 59 package bumps the refresh produced, 52 are kept and 7 were pinned back after CI (see What got pinned back below).Highlights of what's kept:
git2.54.0 → 2.55.0,fd10.4.2 → 10.5.0,nodejs-slim26.7.0 → 26.8.1nodejs25.8.1 → 26.8.1,nodejs@1818.19.1 → 18.20.8,bun1.0.33 → 1.3.13,corepack0.35.0 → 0.36.0python3.12.1 → 3.14.4,python33.11.7 → 3.12.8,poetry1.7.1 → 2.4.1,pipenv2023.2.4 → 2026.5.1php8.3.3 → 8.5.9,php81Packages.composer2.6.6 → 2.8.12,php83Extensions.imagick3.7.0 → 3.8.1, xdebug 3.3.1 → 3.5.3postgresql17.5 → 18.6,redis7.2.4 → 8.10.1,valkey7.2.5 → 9.1.1,mariadb11.0.4 → 11.8.8,mysql808.0.36 → 8.0.45nginx1.24.0 → 1.30.4,caddy2.7.6 → 2.11.4,apache2.4.58 → 2.4.68ghc9.4.8 → 9.10.3,cabal-install3.10.2.1 → 3.16.1.0,gradle8.6 → 8.14.4,maven3.9.6 → 3.9.16ruby4.0.2 → 4.0.6,rustup1.26.0 → 1.29.0,minikube1.32.0 → 1.38.1,fnm1.35.1 → 1.39.0,openssl3.0.13 → 3.6.0, R packages--sync-lockalso harmonised the sharedgithub:NixOS/nixpkgs/nixpkgs-unstablestdenv entry — all 21 lockfiles carrying it now agree on the same pin (2026-08-03), where they previously diverged.Unversioned
"source": "nixpkg"entries (e.g.kubectl,docker,pdm) are untouched, which is whatdevbox updatedoes for them.What got pinned back
CI found six broken examples; each was root-caused from the job logs.
Upstream problems with the new package — pinned back, rest of the lockfile keeps its bumps:
go1.27.0 → 1.26.3nix/flake/flakeref_test.go, andgolangci-lint v1.64.8(pinned in go.mod) panicked five analyzers on 1.27 ASTs. Worth revisiting once golangci-lint supports 1.27.dotnet-sdk8.0.424 → 6.0.418libhostfxr.soresolves against the runner's system glibc and needsGLIBC_ABI_GNU2_TLS, which it doesn't exportjdk@1919-ga → 19.0.2+7Package 'openjdk-19-ga' … is marked as insecure, refusing to evaluate. JDK 19 is EOL — moving these examples to a supported JDK is the durable fix, but that's an example change, not a lockfile refresh.libffi3.8.0 → 3.4.4stack3.9.3 → 2.13.1aarch64-darwinbuild upstream, dropping Apple Silicongradle8.14.4,maven3.9.16 andbinutils2.46 are unaffected by thejdkpin and stay.Bumps that were fine — the example needed updating instead:
poetry-pyproject-subdir: Poetry 2.x makesNo file/folder found for package poetry-pyproject-subdir-servicea hard error where 1.7 only warned. This example uses Poetry purely for dependency management and has noservice/package, so it now declarespackage-mode = false, Poetry's own suggested remedy.poetry-demohas a real package directory and already passes on 2.4.1, sopoetrystays at 2.4.1 in both.stacks/rails: the Gemfile pinnedruby "4.0.2"exactly, soruby4.0.6 failed withYour Ruby version is 4.0.6, but your Gemfile specified 4.0.2. Moved the pin andGemfile.lock'sRUBY VERSIONto 4.0.6, keeping the bump.Platform coverage — please read before merging
Beyond the two reverts above, this refresh drops 30
x86_64-darwinblocks fromsystemsmaps across ~19 lockfiles, because the newer versions no longer publish an Intel-mac build upstream. Affected packages includeredis,postgresql,mysql84,valkey,python311,nginx,php,fdandgit.This is inherent to taking the upgrade, not an artifact of how the update was run —
search.devbox.shresolves all platforms server-side, and querying it directly confirms e.g.fd10.4.2 has all four systems while 10.5.0 has three. Reverting all of them would undo most of this PR, so they stand. Flagging it explicitly so it isn't a silent consequence; happy to pin specific packages back if Intel-mac coverage matters more than the version bump.How was it tested?
cli-tests), including theproject-tests-onlymatrix that builds every example. Each failure was root-caused from job logs rather than guessed at, and re-run after each fix.devbox updateresolves local flake refs (path:my-php-flake#phpand friends inexamples/flakes/*) to an absolute path on the machine that ran it; those four entries were restored to their committed values.One caveat:
Gemfile.lock'sRUBY VERSIONwas written asruby 4.0.6p0, guessing the patchlevel. Bundler's hard check is the Gemfile directive andbin/bundle installrewrites that block, so it should be inert, but it's worth a glance.Note on scope
The sandbox that produced this branch blocks
api.github.comfor repositories outside this one, sonix flake metadata github:NixOS/nixpkgs/nixpkgs-unstablecould not run. Thenixpkgs-unstablestdenv entry was therefore not re-resolved against upstream — only synced to the newest value already in the repo. Everything else resolved normally throughsearch.devbox.sh. A maintainer re-runningdevbox update --all-projectslocally would additionally advance that one pin.Community Contribution License
All community contributions in this pull request are licensed to the project
maintainers under the terms of the
Apache 2 License.
By creating this pull request, I represent that I have the right to license the
contributions to the project maintainers under the Apache 2 License as stated in
the
Community Contribution License.
🤖 Generated with Claude Code
https://claude.ai/code/session_015RaccMofrSPEL7v8RzpoWb