Skip to content

Fork audit selects hundreds of unrelated packages

scope: generic · severity: trap · confidence: proven · subsystem: build

Symptom — an upstream audit or missing-package build selects hundreds of packages that the project does not maintain, or fails its matrix-size limit.

Cause — a Git merge base describes shared history, not ownership. Rewritten history can move that base years back while the current downstream patch set remains small. Caching cannot repair an incorrect build selection.

What to do — keep maintained aports in the profile/shared manifests and resolve those names against the actual checkout. Reject missing or ambiguous paths. Keep changed-package detection for pull requests separate from the maintained-package inventory. Record missing profile packages in the audit; a smaller matrix is not success if required packages vanished from it.