Repository navigation
Conversation
Current head:
|
…ay-recorded-clock
myevolve
left a comment
There was a problem hiding this comment.
Independent AI-assisted technical review
Reviewed 49b4c7532aa9fbeb59b300432713bd1b5ed859ea with a separate clock/lifecycle reviewer: all 12 changed files and affected CLI/container/output callers. No actionable correctness findings were identified.
Parent verification: built this exact CLI head and replayed all three unchanged npm fixtures against the combined, repaired Core sources. The generated full YAML outputs are byte-identical to the committed fixtures; no input or expected-output weakening was used. The reviewer performed static review only, not those runtime checks.
This is an explicitly AI-authored technical COMMENT, not maintainer approval. It does not satisfy required independent-human reviews or publish a CLI release.
Problem
HTTP caches preserve registry metadata but not the clock used to evaluate release age. The same native npm input selected a different version after its cooldown expired. This is the replay-time boundary documented in dependabot/smoke-tests#592, separate from the resolver/writer policy correction in dependabot/dependabot-core#16492.
Change
input.recorded-atfor new output recordings; propagate explicit timestamps through update, graph and test; preserve the timestamp in replay output.Time.nowand JavaScriptDatepreloads, inherited by native npm. Use a shell wrapper so existingRUBYOPT/NODE_OPTIONSremain intact.Verification
Failing-before/passing-after native regression: the Oct 2 input previously reported the Oct 7 Ruby clock and selected npm version 1.1.0. It now selects 1.0.0, a later Oct 7 input selects 1.1.0, and replaying the original selects 1.0.0 again. The test also exercises running timers and unchanged explicit-date parsing.
Standalone CLI with the real unmodified Core updater image, Node 24.21.0, npm 11.19.0, a stable local source revision, and cached public metadata:
Original and replay YAML are byte-identical (7,680 bytes); replay used 20/20 cached HTTP calls. Automatic timestamp capture, legacy JSON replay without a timestamp, and ordinary unpinned updates were also exercised. A separate offline runtime check preserved existing Ruby/Node options, Ruby timezone keywords, and Date constructors/subclasses.
Passed:
go vet ./...,go mod tidy -diff,go build ./..., andgo test -shuffle=on -count=2 -race -cover -timeout=15m -parallel=2 ./...across all five packages. The exact CI command first exhausted its five-minute deadline during local Docker fixture setup; the same complete repeated race suite passed with the local envelope above. CI configuration is unchanged.Two independent static reviews found no actionable defects.
Boundary
This does not rewrite the three existing smoke fixtures or claim they are now green. They need re-recording with a consistent updater and captured time; the separately documented native ignored-version cap limitation is not changed. Other runtimes' clocks and Ruby time APIs other than
Time.noware not overridden.Integration with v1.94.0
Updated to
49b4c7532aa9fbeb59b300432713bd1b5ed859eaby merginge166a3ed59c7d96aca1f4e12c64478ff72beb224from main, including #667's container-isolation changes. The merge was clean; no isolation controls, capabilities, seccomp checks, or setup-error handling were removed or relaxed.go test -race ./...passed across all five packages; the standalone CLI build passed.input.recorded-atand updater logs use the host clock. That release does not satisfy this PR's replay-clock contract; this is why complete-output comparison remains necessary.The dependent migration remains dependabot/smoke-tests#593. This PR changes neither its ignore caps nor production cooldown policy. Maintainer review and a subsequent release containing this clock change are still required.