Skip to content

Repository files navigation

winget-pkgs-updates

PR repo: winget-pkgs Fork repo: damn-good-b0t/winget-pkgs

Pull requests:

Package Version Handling Count
Script based Script based Packages
GitHub Release based GitHub based Packages

Package-specific WinMatsch overrides

Keep safety questions enabled by default. When a package has reviewed, stable exceptions, add a WinMatsch override-pack YAML file to the repository and set its matrix entry's overridePack field to that repository-relative path:

- id: Publisher.App
  repo: publisher/app
  url: https://github.com/publisher/app/releases/download/v{VERSION}/setup.exe
  overridePack: overrides/Publisher.App.yaml

The single-package workflow exposes the same path as overridePack. The wrapper rejects missing files and rejects override packs with Komac or WinGetCreate, so an override cannot be silently ignored.

For a reviewed installer architecture, type, or scope transition, set allowStructuralRewrite: true on that package's matrix entry. This approval is disabled by default and maps only to WinMatsch's --allow-structural-rewrite option.

If the published winget manifest declares the wrong installer architecture and the new generated manifest intentionally corrects it for the same installer URL pattern, also set allowArchitectureMigration: true on that package's matrix entry. Use this narrowly after verifying the payload's PE machine type; it only approves the repository guard that compares generated installer architectures with the previously published manifest.

Editing the monitored list

github-releases-monitored.yml is the source of truth, but the workflows read the generated sidecar .github/workflows-data/update-github-packages-*.packages.json. After every edit (adding, retiring or reconfiguring a package) regenerate the sidecar and commit it together with the yml:

pip install pyyaml
python scripts/orchestrate_gh-packages.py

tests/GitHubReleaseMonitoringConfiguration.Tests.ps1 fails when the sidecar and the yml disagree, so a retired package can no longer keep being submitted because the regeneration step was skipped. Retire a package by commenting out its entry and adding a # <Id> is excluded: <reason> note above it; scripts/Disable-ReAddedExcludedPackages.ps1 re-applies documented exclusions.

The update precheck's Config Health submission gate shows stored findings from the weekly Config Health workflow, not fresh download failures. After repairing a repository or asset rename, check the affected entries with Test-MonitoredPackageAssets. Also verify whether the publisher already maintains the moved project under a new winget identifier before re-enabling an old one; if so, retire the old identifier instead of submitting duplicate installer hashes. Only after every configured asset resolves, clear their configHealth markers with Update-PackageStateConfigHealth and include the state change with the configuration repair; otherwise the packages stay blocked until Config Health runs again. Preserve validation failures and open-PR state. A missing architecture or an installer-type change is not a filename rename and needs a separate migration review.

Submission policies

Besides the duplicate-PR and published-version checks, manifest generation stops (reason in the job output) when one of these holds applies:

Reason Rule
ReleaseTooFresh The GitHub release is younger than the minimum age, measured from the newest of the release's publish time and the upload time of the assets the package uses. Disabled by default (0); set globally via WINGET_MIN_RELEASE_AGE_HOURS or per package via minReleaseAgeHours on the matrix entry, e.g. 48 for packages whose publisher files their own PR within a day.
BlockedByUpstreamValidation The bot's previous PR for the identical version was closed unmerged with a blocking label (Validation-Defender-Error, Binary-Validation-Error, Validation-Certificate-Root, URL-Validation-Error, Validation-Unattended-Failed, Validation-Installation-Error, Validation-Shell-Execute, Blocking-Issue, DriverInstall). A new upstream version is submitted normally.
BlockedByUpstreamVerdict WinMatsch's committed upstream verdict store blocks repeats of a rejected version, unchanged installer traits after an installation failure, rejected URLs that are still present, and certificate rejections. Verdicts expire after 30 days and are pruned when the associated winget-pkgs PR merges. Set ignoreUpstreamVerdict: true on a reviewed matrix entry to pass --ignore-upstream-verdict and bypass the hold.
HeldForWaivedValidation The bot's open PR for an older version carries a moderator Waived-* label. Newer versions wait up to 30 days from the waiver/PR creation so a granted validation waiver is not lost by superseding the PR.

The update precheck additionally skips ChannelCooldown packages: identifiers ending in .Nightly, .Beta, .Preview, .PreRelease or .Canary run at most once every 3 days, regardless of the previous run's verdict.

Numeric-stream identifiers (OpenJS.Electron.41) must pin their stream with a tagPattern; generation additionally fails closed when the resolved version does not start with the pinned number.

End-to-end installer analysis

scripts/analyze/Invoke-InstallerE2E.ps1 answers "what would our pipeline do with this installer?" without touching any monitored package:

# Direct URL(s)
./scripts/analyze/Invoke-InstallerE2E.ps1 -InstallerUrl 'https://example.com/setup.exe'

# Any winget-pkgs PR - installer URLs are extracted from the PR's manifests
./scripts/analyze/Invoke-InstallerE2E.ps1 -WingetPkgsPr 421311

It runs winmatsch analyze per URL (architecture, installer type, silent switches, hashes, dependencies), generates a throwaway manifest with winmatsch new under a demo identifier (nothing is submitted), validates it, and - when Windows Sandbox is enabled - installs it via scripts/validation/Test-Manifest-Sandbox.ps1. report.md and report.json are written to data/e2e-analysis/<timestamp>/ (gitignored). Use -SkipSandbox, -SkipManifest, or -SkipAnalyze to shorten the loop.

About

keeps software in winget up to date

Resources

Stars

7 stars

Watchers

1 watching

Forks

Used by

Contributors

Languages