From 99b4cb1b553343e386cb1bd43114692993182130 Mon Sep 17 00:00:00 2001 From: Tyler Stapler Date: Wed, 30 Sep 2026 23:43:42 -0700 Subject: [PATCH] ci(bazel): vendor InfoZip unzip/zip tarballs to stop SourceForge 522s from breaking CI downloads.sourceforge.net had intermittent Cloudflare 522 outages on 2026-10-01 that broke multiple PR CI runs and shipped v0.89.0 with zero release assets (the safety-gate job exhausted its retries fetching unzip60.tar.gz/zip30.tar.gz). Both tarballs are now mirrored as GitHub release assets on this repo (sha256-verified byte-identical to the originals) and listed first in MODULE.bazel's http_archive urls, with MacPorts/OSUOSL as independent fallbacks and SourceForge demoted to last. --- MODULE.bazel | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/MODULE.bazel b/MODULE.bazel index c87a385df..9ab1f2a85 100644 --- a/MODULE.bazel +++ b/MODULE.bazel @@ -72,7 +72,16 @@ android_sdk_repository_extension.configure( http_archive = use_repo_rule("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive") http_archive( name = "unzip_src", - urls = ["https://downloads.sourceforge.net/infozip/unzip60.tar.gz"], + # SourceForge's downloads.sourceforge.net CDN has intermittent Cloudflare 522 outages + # (broke CI and the v0.89.0 release build on 2026-10-01). Our own GitHub release is tried + # first since we control its availability; the other mirrors are independent fallbacks, + # all verified byte-identical (sha256 below) to the original SourceForge tarball. + urls = [ + "https://github.com/tstapler/stelekit/releases/download/ci-vendored-deps-infozip-v1/unzip60.tar.gz", + "https://distfiles.macports.org/unzip/unzip60.tar.gz", + "https://ftp.osuosl.org/pub/blfs/conglomeration/unzip/unzip60.tar.gz", + "https://downloads.sourceforge.net/infozip/unzip60.tar.gz", + ], sha256 = "036d96991646d0449ed0aa952e4fbe21b476ce994abc276e49d30e686708bd37", strip_prefix = "unzip60", build_file = "//:third_party/unzip.BUILD", @@ -95,7 +104,12 @@ http_archive( http_archive( name = "zip_src", - urls = ["https://downloads.sourceforge.net/infozip/zip30.tar.gz"], + # Same SourceForge-outage rationale as unzip_src above. + urls = [ + "https://github.com/tstapler/stelekit/releases/download/ci-vendored-deps-infozip-v1/zip30.tar.gz", + "https://ftp.osuosl.org/pub/blfs/conglomeration/zip/zip30.tar.gz", + "https://downloads.sourceforge.net/infozip/zip30.tar.gz", + ], sha256 = "f0e8bb1f9b7eb0b01285495a2699df3a4b766784c1765a8f1aeedf63c0806369", strip_prefix = "zip30", build_file = "//:third_party/zip.BUILD",