Background
UpdatesCollector.Collect (internal/collector/updates.go) shells out to apt list --upgradable and parses its stdout with a regex to determine the number of available package updates.
apt itself warns about this approach:
WARNING: apt does not have a stable CLI interface. Use with caution in scripts.
#100 fixed the immediate symptom of this fragility (output was locale-dependent, silently producing wrong results on non-English systems, now fixed by pinning LC_ALL=C/LANG=C/LANGUAGE=). But the underlying approach — parsing human-readable apt CLI output — remains inherently brittle: future apt versions could change the output format again in ways a locale fix won't help with.
Suggested follow-up
Investigate replacing the apt list --upgradable + regex approach with something more stable, e.g.:
apt-get --just-print upgrade (also CLI output, but worth evaluating if it's more stable)
- Reading dpkg/apt state directly (e.g. via
/var/lib/dpkg/status and the apt package cache/lists in /var/lib/apt/lists), avoiding a CLI-output dependency entirely
- Any other approach that avoids depending on
apt's unstable human-readable CLI output
This is intentionally a larger, exploratory change and was out of scope for #100's minimal locale fix — see the "Alternative worth considering" section there for context.
Constraints to keep in mind
- Per
docs/CONTRIBUTING.md / docs/ARCHITECTURE.md, this project hand-rolls /proc- and /sys-parsing rather than pulling in dependencies like gopsutil; any replacement should stay dependency-free (standard library only, per CLAUDE.md).
UpdatesCollector must stay usable without elevated privileges — the root-privileged apt cache refresh is handled by a separate systemd timer, and this collector only ever reads.
- Needs fixture-based unit tests per
docs/TESTS.md (no real /proc//sys/apt access in tests).
- If the JSON shape of
/api/v1/... updates output would change as part of this, that's a breaking API change — bump to /api/v2/... instead, per CLAUDE.md.
Related
Follow-up to #100.
Background
UpdatesCollector.Collect(internal/collector/updates.go) shells out toapt list --upgradableand parses its stdout with a regex to determine the number of available package updates.aptitself warns about this approach:#100 fixed the immediate symptom of this fragility (output was locale-dependent, silently producing wrong results on non-English systems, now fixed by pinning
LC_ALL=C/LANG=C/LANGUAGE=). But the underlying approach — parsing human-readableaptCLI output — remains inherently brittle: futureaptversions could change the output format again in ways a locale fix won't help with.Suggested follow-up
Investigate replacing the
apt list --upgradable+ regex approach with something more stable, e.g.:apt-get --just-print upgrade(also CLI output, but worth evaluating if it's more stable)/var/lib/dpkg/statusand the apt package cache/lists in/var/lib/apt/lists), avoiding a CLI-output dependency entirelyapt's unstable human-readable CLI outputThis is intentionally a larger, exploratory change and was out of scope for #100's minimal locale fix — see the "Alternative worth considering" section there for context.
Constraints to keep in mind
docs/CONTRIBUTING.md/docs/ARCHITECTURE.md, this project hand-rolls/proc- and/sys-parsing rather than pulling in dependencies likegopsutil; any replacement should stay dependency-free (standard library only, perCLAUDE.md).UpdatesCollectormust stay usable without elevated privileges — the root-privileged apt cache refresh is handled by a separate systemd timer, and this collector only ever reads.docs/TESTS.md(no real/proc//sys/apt access in tests)./api/v1/...updatesoutput would change as part of this, that's a breaking API change — bump to/api/v2/...instead, perCLAUDE.md.Related
Follow-up to #100.