Repository navigation
Conversation
Current verification:
|
…transitive-version-policy
There was a problem hiding this comment.
Independent AI-assisted technical review
Reviewed the original PR and re-reviewed the repairs now published at 683673c7fb7831c7a5715abb15f2b4055bff495d. The independent Core reviewer found three reproducible policy holes, all now fixed:
- v1 lockfiles bypassed validation because only the modern
packagestable was traversed. - Removing a nested occurrence could rebind its consumer to an unchanged, over-cap ancestor installation.
- An alias could change package identity at the same installation path while presenting an otherwise compliant version.
Production-Ruby before/after probes demonstrated the unsafe cases changing from accepted to rejected. The final re-review found no remaining actionable correctness defect; unchanged effective higher versions and normalized legacy-to-modern alias conversions remain supported.
Parent verification on the final implementation: 85 helper/parser examples passed, repository-configured Sorbet passed, and RuboCop passed all four changed Ruby files. The rebuilt CLI at 49b4c75 also replayed npm, group-rules, and group-semver with the combined repaired Core sources; all full generated YAMLs were byte-identical to the unchanged #593 fixtures. Broader native integration specs and fresh upstream CI are separate from this focused evidence.
This is an explicitly AI-authored technical COMMENT, not maintainer approval. Earlier CI counts in the thread belong to their recorded older heads, not this new commit.
Legacy contract follow-up
The initial full CI run at 683673c exposed two stale acceptance assertions, not a reason to relax the validator. Actual native npm resolution on the untouched legacy fixture changes root Acorn 5.5.3→5.7.4 and nested Acorn 6.1.1→6.4.2, while those examples requested a 6.0.2 cap. Returning no resolvable update is correct.
Final test/documentation-only head: 17d417e99102a7567762baebd43bccb4f60ba19e. The two cases now require rejection; a positive control allows 6.4.2 and expects the enabled all-occurrences resolver to return 6.4.2. The independent reviewer re-checked this final contract and found no remaining actionable issue. Production validation and all fixture expectations remain unchanged from the replayed implementation.
Canonical CI for the final head passed: 2283 examples, 0 failures, 4 pending in the npm suite, and all 21 required checks passed. The earlier failing run remains historical; it was not relabeled green.
Problem
Native
npm updateaccepts package names, not per-package version constraints. Core passed only the name, so a resolver cap/ignore rule could be bypassed by the actual lockfile, and the writer could write a different version from the one requested. Clamping parsed metadata alone does not constrain the file.Change
UpdateNotPossibleif npm exceeds the requested version. Keep the previous-state diagnostic probe unchanged so registry failures retain their original classification.Initial feature verification
srbwrapper injects a mismatched/duplicate gem RBI set; the same installed Sorbet static executable was run directly against repository config instead.^1.15.9, external networking disabled:UpdateNotPossibleSource manifests remain unchanged. The grouped registry-error regression also failed before moving the guard to the publication path and passes afterward. Independent correctness and failure-path reviews completed; the diagnostic finding was reproduced and fixed.
Boundary
This intentionally rejects an out-of-policy native result; it does not promise to make npm search for an older allowed transitive candidate. Temporary overrides would replace parent requirements rather than safely intersect them. That limitation is documented.
Related: dependabot/smoke-tests#592. Independently based on current main, not stacked on #16490 or #16492; it does not modify those PR branches or existing smoke expectations. Clocked regeneration using dependabot/cli#668 is being exercised separately with original ignore conditions preserved.
Current integration verification
Head:
de4a7cb8bf466b2667fdb4b8bc5948a1061d86c2, incorporating main0286aa0868b1f0de1b908ce3358bbf994e5272c1(Julia stdlib notices and shared INFO/fallback alert rendering). The npm implementation, input policy and fixture expectations are unchanged by this merge.[!NOTE]; WARN remains[!WARNING], ERROR remains[!IMPORTANT].260f77e6e25e0b6cbcf00882ada974398de69a82; the subsequent spec-only isolation commit leaves all mounted npm/common/updater runtime libraries unchanged.de4a7cb8bf466b2667fdb4b8bc5948a1061d86c2: package-manager specs left npm selectors active across examples, producing 24 failures in the previous full npm run. Shared cleanup now resets both active and per-directory selectors after each example; redundant local cleanup hooks were removed. The existing two-example reproducer fails before / passes after, the complete previously failing worker passes 564 examples, 0 failures at seed 16904, all five changed Ruby files pass RuboCop, and full-repository Sorbet reports no errors. No production runtime code, cooldown/ignore guard or fixture contract changed.21/21 required checks passed; 65 successful / 3 failed / 4 skipped check records, none pending. Full npm/yarn CI at
de4a7cb8bf466b2667fdb4b8bc5948a1061d86c2: 2231 examples, 0 failures, 4 existing pending, seed 28164. The previous 24 required-spec failures are resolved.Smoke actually ran 13 E2E jobs: 10 passed both the test and
Diffsteps, 3 failed. npm and rules omit the out-of-policy follow-redirects 1.16.1 / form-data 4.0.6 PRs still expected by main fixtures; cache coverage is 124/197 and 122/196. semver omits those dependencies from the expected group and has corresponding lockfile/metadata differences, with 148/223 cached calls. All three used released CLI v1.94.0 and main fixtures/official caches, not draft #593. These failures remain visible; no baseline-identical or released-toolchain-pass claim is made.Maintainer review remains required. REST confirms
dependabot/maintainersis already requested on all three Core prerequisite PRs and CLI #668; CLI also requestsdependabot/azure-dev-ops. Emptygh pr viewreviewer lists hid these existing team requests. The later individual requests forJamieMageeandjakecoffmanreturned HTTP 404 and added no individual reviewers; no duplicate request was made. The independent discovery fix #16498 remains separate; fixtures stay draft pending releases, official cache refreshes and released-toolchain Smoke.Independent AI review follow-up
Current head:
17d417e99102a7567762baebd43bccb4f60ba19e; runtime implementation remains683673c. Independent review fixed legacy-v1 bypass, unsafe removed-occurrence rebinding, and alias-identity substitution. AI review and before/after evidence. Focused checks passed: 85 examples, Sorbet, changed-file RuboCop, and three byte-identical full npm fixture replays.Full CI then exposed two old npm6 assertions accepting root 5.7.4 despite a nested occurrence changing to 6.4.2 under a 6.0.2 cap. The test-only follow-ups now require rejection and include a compliant 6.4.2 positive control; no production guard or fixture expectation was weakened. Final-head CI passed: 2283 npm examples, 0 failures, 4 pending; all 21 required checks pass. Earlier CI counts above are historical. This AI technical review is not maintainer approval.