跳转至

本周包管理生态回顾:2026年7月11日

背景与摘要

本文是2026年7月11日那一周包管理领域的动态汇总,涵盖了多个主要包管理器的最新发布版本(如npm 12和Rust 1.97.0等)及安全公告(如opam和pnpm的重要补丁)。此外,文章还推荐了关于Packagist不可变版本和受信任发布机制(Trusted Publishing)的文章和观点,展示了行业对软件供应链安全的持续关注和生态系统的发展。

这是包管理回顾的第八周,内容精选自 包管理器 OPML 订阅源集合以及 Mastodon 上的帖子/转发。

Week eight of the package management roundup, curated from the package manager OPML feed collection and posts/boosts on Mastodon.


📌 Summary

本周的回顾重点介绍了整个生态系统中的主要版本发布——包括 npm 12 中严格的默认设置、opampnpm 的安全补丁,以及 Rust 1.97.0 中新的缓存和配置改进。关键讨论集中在 Packagist 上的不可变版本、受信任发布 (Trusted Publishing) 的局限性,以及 Trail of Bits 针对 PyPI 提出的透明度日志。

This week's roundup highlights major version releases across the ecosystem—including strict default settings in npm 12, security patches for opam and pnpm, and new caching and config improvements in Rust 1.97.0. Key discussions focus on immutable versions on Packagist, limitations of Trusted Publishing, and a proposed transparency log for PyPI by Trail of Bits.


🚀 Releases

  • npm 12.0.0: 引入了破坏性变更。allow-gitallow-remote 现在默认为 none,要求明确选择加入 git 依赖或远程 tarball。npm shrinkwrap 已被移除,未知的 .npmrc 键/标志现在会抛出错误,根目录的 preinstall 在依赖安装之前运行,而诸如 npm adduserstarunstar 等命令被弃用/移除。
    • npm 12.0.0: Introduces breaking changes. allow-git and allow-remote now default to none, requiring explicit opt-ins for git dependencies or remote tarballs. npm shrinkwrap has been removed, unknown .npmrc keys/flags now throw errors, root preinstall runs prior to dependency installation, and commands like npm adduser, star, and unstar are deprecated/removed.
  • pnpm 11.10 & 11.11.0: 添加了 _auth 设置以简化 CI 注册表凭据,以及像 pnpm prefixpnpm issuespnpm access 这样的新命令。allowBuilds 现在支持通过存储库 URL 匹配,而无需固定提交哈希。(版本 11.11.0 还包含关键安全补丁)
    • pnpm 11.10 & 11.11.0: Adds an _auth setting for simplified CI registry credentials, alongside new commands like pnpm prefix, pnpm issues, and pnpm access. allowBuilds now supports matching via repository URLs without pinning commit hashes. (Version 11.11.0 also includes critical security patches).
  • uv 0.11.28: 通过 astral-async-zip 加固了针对解析器差异的 ZIP 处理。之前的 0.11.27 带来了显著的解析器性能升级。
    • uv 0.11.28: Hardens ZIP handling against parser differentials via astral-async-zip. Preceded by 0.11.27, which brought significant resolver performance upgrades.
  • Go 1.26.5 & 1.27rc2: 一次安全发布,修复了 crypto/tlsos 中的问题,以及常规的编译器和运行时修复。
    • Go 1.26.5 & 1.27rc2: A security release patching issues in crypto/tls and os, alongside general compiler and runtime fixes.
  • Rust 1.97.0: 稳定了 Cargo 配置中用于外部锁文件的 resolver.lockfile-path 以及 build.warnings,可将警告转变为错误而不会使构建缓存失效。
    • Rust 1.97.0: Stabilises resolver.lockfile-path in Cargo config for external lockfiles and build.warnings to turn warnings into errors without invalidating the build cache.
  • winget 1.29: 为包搜索解析引入了实验性的源优先级功能。
    • winget 1.29: Introduces an experimental source priority feature for package search resolution.
  • Spack 1.2.1: 修复了安装程序在 forkserver 下挂起的问题,并恢复了 macOS 求解器的性能。
    • Spack 1.2.1: Fixes installer hangs under forkserver and restores macOS solver performance.
  • CocoaPods 1.17.0:pod repo push 添加了 --no-lint,并为可合并库更新了 ruby-macho
    • CocoaPods 1.17.0: Adds --no-lint to pod repo push and updates ruby-macho for mergeable libraries.
  • Hex 2.5.1:mix.exs 和环境变量添加了 ignore_advisoriesignore_retirements 配置。
    • Hex 2.5.1: Adds ignore_advisories and ignore_retirements configurations to mix.exs and environment variables.
  • mise 2026.7.4 & 2026.7.5: 使得 mise bootstrapmise dotfiles 结束了实验模式,并跨 git 工作树共享配置信任。
    • mise 2026.7.4 & 2026.7.5: Graduates mise bootstrap and mise dotfiles out of experimental mode and shares config trust across git worktrees.

Other Notable Releases: Homebrew 6.0.9, RubyGems / Bundler 4.0.16, Cargo 0.98.0, asdf 0.20.0, Hatch 1.17.1, pixi 0.72.2, Yarn 4.17.1, Deno 2.9.2, Helm 4.2.3 / 3.21.3, Podman 6.0.1, Nix 2.34.8, Gradle 9.7.0-M3, Maven 3.10.0-rc-1, Renovate 43.258.0, 以及 Dependabot Core 0.385.0

Other Notable Releases: Homebrew 6.0.9, RubyGems / Bundler 4.0.16, Cargo 0.98.0, asdf 0.20.0, Hatch 1.17.1, pixi 0.72.2, Yarn 4.17.1, Deno 2.9.2, Helm 4.2.3 / 3.21.3, Podman 6.0.1, Nix 2.34.8, Gradle 9.7.0-M3, Maven 3.10.0-rc-1, Renovate 43.258.0, and Dependabot Core 0.385.0.


🔒 Security Advisories

  • opam 2.5.2: 修复了 CVE-2026-57825,防止包通过外部目录的符号链接任意安装文件并绕过用户提示。
    • opam 2.5.2: Fixes CVE-2026-57825, preventing packages from installing files arbitrarily via symlinks to external directories, bypassing user prompts.
  • pnpm (11.11.0 / 10.34.5): 修复了两个关键的路径遍历漏洞,防止精心构造的锁文件和恶意包清单写入目标目录(node_modules 和虚拟存储)之外。
    • pnpm (11.11.0 / 10.34.5): Fixes two critical path traversal vulnerabilities preventing crafted lockfiles and malicious package manifests from writing outside target directories (node_modules and virtual stores).
  • ORAS 1.3.3: 更新到 oras-go 2.6.2 以修补 GHSA-fxhp-mv3v-67qp / CVE-2026-50163,防止精心构造的 OCI 构件在 oras pull 期间链接到宿主机文件中。

📝 Articles & Opinions

  • Immutable Versions on Packagist (Packagist Blog): 详细介绍了 Composer 的最新供应链安全升级。稳定版本现在会锁定其 git 引用,阻止重新打标签的尝试,并将删除操作变为带有透明度日志的软删除。
    • Immutable Versions on Packagist (Packagist Blog): Details the latest supply chain security upgrades for Composer. Stable versions now lock their git references, blocking retag attempts and turning deletions into soft deletes with transparency logs.
  • You shouldn’t trust Trusted Publishing (William Woodruff): 认为受信任发布(Trusted Publishing)严格来说只是 CI 系统和注册表之间的认证机制,而不是包安全性的指标。
    • You shouldn’t trust Trusted Publishing (William Woodruff): Argues that Trusted Publishing is strictly an authentication mechanism between CI systems and registries, not an indicator of package safety.

🌐 Elsewhere in the Ecosystem

  • PyPI Transparency Logs: Trail of Bits 发布了一项透明度日志提议,其特点是提供被服务的分发文件的仅追加日志,以检测索引级别的篡改。包括 草案 PEP源代码
  • EuroPython 2026 Packaging Summit: 7 月 13 日在克拉科夫的日程安排已上线,旁边还有公开笔记
    • EuroPython 2026 Packaging Summit: The schedule for July 13 in Kraków is live, alongside public notes.
  • Rust Foundation Maintainers Fund: Josh Bressers 主持了一次播客讨论,与 Lori Lorusso 和 Niko Matsakis 探讨维护资金结构。
    • Rust Foundation Maintainers Fund: Josh Bressers hosts a podcast discussion with Lori Lorusso and Niko Matsakis on maintenance funding structures.
  • Nix Documentation Team: Nix 基金会正在通过 Open Collective 筹集资金,以聘请专门的贡献者来编写用户入门和参考资料。
    • Nix Documentation Team: The Nix Foundation is fundraising via Open Collective to hire dedicated contributors for user onboarding and reference materials.
  • Git 2.55: 亮点包括用于简化提交的 git history fixup <commit>、增量多包索引重新打包,以及原生的 Linux inotify 监控。
    • Git 2.55: Highlights include git history fixup <commit> for streamlined commits, incremental multi-pack index repacking, and native Linux inotify monitoring.
  • SBOM Completeness Study: 一篇新的学术论文《超越合规:关于 GitHub SBOM 完整性和一致性的大规模研究》(Bhuiyan 等人,arXiv),强调了自动生成的 SBOM 可靠性在不同语言中存在的差距。

📦 git-pkgs Releases

本周标记了六个存储库:

Six repositories were tagged this week: * brief v0.9.3 * brief v0.9.3 * enrichment v0.6.0 * enrichment v0.6.0 * purl v0.1.14 * purl v0.1.14 * sarif v0.1.0 * sarif v0.1.0 * sbom v0.1.3 * sbom v0.1.3 * vulns v0.2.0 * vulns v0.2.0


有下周的链接或发布吗?请发送至 @andrewnez@mastodon.social

Got links or releases for next week? Send them to @andrewnez@mastodon.social.