## Pacman

[Pacman v7.0.0][0] has been released as a major feature version. A new `DownloadUser` configuration option allows for dropping privileges when downloading files to a temporary directory. On top of this security measure, the new Landlock sandbox also prevents writing outside the restricted download directory.

Additionally, `makepkg` removes `GITFLAGS` support, as it required breaking changes to git source handling. Furthermore this release addresses unstable git checksumming influenced by specific user configuration. On top, it now prevents `PKGBUILD` from overriding `BUILDENV` to avoid undesired side effects.

## ArchWeb

We have released [ArchWeb 2024-07-29][1], featuring improvements in rebuilderd integration for reproducible builds status, enhanced caching for several pages, and implementation of a Django Prometheus exporter for better monitoring inside our Grafana dashboards.

## ArchISO

[ArchISO v79][2] is a minor update that introduces reproducibility for the ext4 image, thanks to improvements related to `tune2fs`.

## infrastructure

ArchWeb now exports Prometheus metrics via the `/metrics` endpoint, including request duration data. We are now scraping the endpoint and added visualization in our Grafana dashboards.

## SPI

We have drafted a project status update highlighting our major achievements and key focus areas for the [2023 Annual SPI Report][3].

## Packaging

### Statistics

In this month, we’ve successfully rolled out 6084 package updates addressing various enhancements and rebuilds, including 2476 package upgrades. Additionally, we’ve received 200 new package issues, while resolving a total of 143 issues.

[0]: https://gitlab.archlinux.org/pacman/pacman/-/releases/v7.0.0
[1]: https://github.com/archlinux/archweb/releases/tag/release_2024-07-29
[2]: https://gitlab.archlinux.org/archlinux/archiso/-/tags/v79
[3]: https://www.spi-inc.org/corporate/annual-reports/2023.pdf

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to