PR repo: winget-pkgs Fork repo: damn-good-b0t/winget-pkgs
| Package Version Handling | Count |
|---|---|
| Script based | |
| GitHub Release based |
Keep safety questions enabled by default. When a package has reviewed, stable
exceptions, add a WinMatsch override-pack YAML file to the repository and set
its matrix entry's overridePack field to that repository-relative path:
- id: Publisher.App
repo: publisher/app
url: https://github.com/publisher/app/releases/download/v{VERSION}/setup.exe
overridePack: overrides/Publisher.App.yamlThe single-package workflow exposes the same path as overridePack. The wrapper
rejects missing files and rejects override packs with Komac or WinGetCreate, so
an override cannot be silently ignored.
For a reviewed installer architecture, type, or scope transition, set
allowStructuralRewrite: true on that package's matrix entry. This approval is
disabled by default and maps only to WinMatsch's --allow-structural-rewrite
option.
If the published winget manifest declares the wrong installer architecture and
the new generated manifest intentionally corrects it for the same installer URL
pattern, also set allowArchitectureMigration: true on that package's matrix
entry. Use this narrowly after verifying the payload's PE machine type; it only
approves the repository guard that compares generated installer architectures
with the previously published manifest.
github-releases-monitored.yml is the source of truth, but the workflows read
the generated sidecar .github/workflows-data/update-github-packages-*.packages.json.
After every edit (adding, retiring or reconfiguring a package) regenerate the
sidecar and commit it together with the yml:
pip install pyyaml
python scripts/orchestrate_gh-packages.pytests/GitHubReleaseMonitoringConfiguration.Tests.ps1 fails when the sidecar
and the yml disagree, so a retired package can no longer keep being submitted
because the regeneration step was skipped. Retire a package by commenting out
its entry and adding a # <Id> is excluded: <reason> note above it;
scripts/Disable-ReAddedExcludedPackages.ps1 re-applies documented exclusions.
The update precheck's Config Health submission gate shows stored findings
from the weekly Config Health workflow, not fresh download failures.
After repairing a repository or asset rename, check the affected entries with
Test-MonitoredPackageAssets. Also verify whether the publisher already
maintains the moved project under a new winget identifier before re-enabling an
old one; if so, retire the old identifier instead of submitting duplicate
installer hashes. Only after every configured asset resolves, clear their
configHealth markers with Update-PackageStateConfigHealth and include the
state change with the configuration repair; otherwise the packages stay blocked
until Config Health runs again. Preserve validation failures and open-PR state.
A missing architecture or an installer-type change is not a filename rename and
needs a separate migration review.
Besides the duplicate-PR and published-version checks, manifest generation stops (reason in the job output) when one of these holds applies:
| Reason | Rule |
|---|---|
ReleaseTooFresh |
The GitHub release is younger than the minimum age, measured from the newest of the release's publish time and the upload time of the assets the package uses. Disabled by default (0); set globally via WINGET_MIN_RELEASE_AGE_HOURS or per package via minReleaseAgeHours on the matrix entry, e.g. 48 for packages whose publisher files their own PR within a day. |
BlockedByUpstreamValidation |
The bot's previous PR for the identical version was closed unmerged with a blocking label (Validation-Defender-Error, Binary-Validation-Error, Validation-Certificate-Root, URL-Validation-Error, Validation-Unattended-Failed, Validation-Installation-Error, Validation-Shell-Execute, Blocking-Issue, DriverInstall). A new upstream version is submitted normally. |
BlockedByUpstreamVerdict |
WinMatsch's committed upstream verdict store blocks repeats of a rejected version, unchanged installer traits after an installation failure, rejected URLs that are still present, and certificate rejections. Verdicts expire after 30 days and are pruned when the associated winget-pkgs PR merges. Set ignoreUpstreamVerdict: true on a reviewed matrix entry to pass --ignore-upstream-verdict and bypass the hold. |
HeldForWaivedValidation |
The bot's open PR for an older version carries a moderator Waived-* label. Newer versions wait up to 30 days from the waiver/PR creation so a granted validation waiver is not lost by superseding the PR. |
The update precheck additionally skips ChannelCooldown packages: identifiers
ending in .Nightly, .Beta, .Preview, .PreRelease or .Canary run at
most once every 3 days, regardless of the previous run's verdict.
Numeric-stream identifiers (OpenJS.Electron.41) must pin their stream with a
tagPattern; generation additionally fails closed when the resolved version
does not start with the pinned number.
scripts/analyze/Invoke-InstallerE2E.ps1 answers "what would our pipeline do
with this installer?" without touching any monitored package:
# Direct URL(s)
./scripts/analyze/Invoke-InstallerE2E.ps1 -InstallerUrl 'https://example.com/setup.exe'
# Any winget-pkgs PR - installer URLs are extracted from the PR's manifests
./scripts/analyze/Invoke-InstallerE2E.ps1 -WingetPkgsPr 421311It runs winmatsch analyze per URL (architecture, installer type, silent
switches, hashes, dependencies), generates a throwaway manifest with
winmatsch new under a demo identifier (nothing is submitted), validates it,
and - when Windows Sandbox is enabled - installs it via
scripts/validation/Test-Manifest-Sandbox.ps1. report.md and report.json
are written to data/e2e-analysis/<timestamp>/ (gitignored). Use
-SkipSandbox, -SkipManifest, or -SkipAnalyze to shorten the loop.