Repository navigation
Conversation
|
Current head
The corrected local integrated replay is independently verified: 3/3 successful, byte-identical, 100% cached (202/202, 200/200, 249/249), with no metadata errors or job errors. The prior semver rate-limit fallbacks were removed through real authenticated public metadata reads, not hand-edited expectations; the updater/proxy never received the write-enabled host credential. Matching local caches are archived, not represented as refreshed official artifacts. Latest runtime heads are Core #16492 Full-repository Sorbet passed on all three refreshed Core branches and again after the policy spec-isolation correction. Direct shared-notice rendering confirms INFO/fallback → NOTE, WARN → WARNING, ERROR → IMPORTANT. Three complete CLI replays at cooldown Core #16492 CI: 21/21 required checks passed; 55 successful / 4 skipped check records. Full npm/yarn specs: 2231 examples, 0 failures, 4 existing pending. No E2E jobs ran: discovery logged Core #16496 CI: 21/21 required checks passed; 65 successful / 3 failed / 4 skipped check records, none pending. Full npm/yarn CI at Smoke actually ran 13 E2E jobs: 10 passed both the test and Core #16498 at Maintainer actions: (1) review/merge the independent discovery workflow fix and obtain genuine runtime-branch E2E evidence; (2) review/merge CLI #668 and Core #16492/#16496, then release the CLI clock support and an updater containing both runtime fixes; (3) run Cache One for Release follow-up: CLI v1.94.0 is now published, but it does not include dependabot/cli#668. The downloaded darwin-arm64 release binary was exercised with the same npm input, integrated Core runtime and preserved cache. Its event comparison exits 0, yet its generated YAML drops |
Gradle/pip-compile follow-up (2026-10-08)The two residual suites are now diagnosed and their clean recordings are published separately in smoke-tests#595, head Actual clean-cache regeneration changes only five uncapped Released CI for #595: pip-compile passes; Gradle still fails. Gradle now creates all four PRs; its sole diff is the 29-line Hibernate release-note block absent from the old cached releases response (75/116 cached). pip-compile is green at 96/130 cached. Suite discovery and yamllint pass. This confirms why matching Cache One artifacts are still required; expectations must not be weakened to accommodate stale metadata. Hosted proof added (23:02 UTC): the unchanged Cache One workflow passes in the writable fork at the same #595 head: Gradle and pip-compile. Both downloadable artifacts were replayed without editing responses: full-YAML byte-identical at 119/119 and 130/130 cached. #595 contains artifact links, upload digests and download commands. This is fork-hosted evidence only; the upstream consumer still requires maintainer-published artifacts in Upstream gate remains: a maintainer must run Cache One at @brettfo — the overlap with #594 remains resolved at The prerequisite team reviews are already requested. Could you help complete review/release of dependabot/cli#668 and dependabot/dependabot-core#16492 / dependabot/dependabot-core#16496, plus review/merge of workflow-only dependabot/dependabot-core#16498? The latter needs no package release. Latest runtime heads are Core #16492 Full-repository Sorbet passed on all three refreshed Core branches and again after the policy spec-isolation correction. Direct shared-notice rendering confirms INFO/fallback → NOTE, WARN → WARNING, ERROR → IMPORTANT. Three complete CLI replays at cooldown Test-isolation follow-up at Core #16492 CI: 21/21 required checks passed; 55 successful / 4 skipped check records. Full npm/yarn specs: 2231 examples, 0 failures, 4 existing pending. No E2E jobs ran: discovery logged Core #16496 CI: 21/21 required checks passed; 65 successful / 3 failed / 4 skipped check records, none pending. Full npm/yarn CI at Smoke actually ran 13 E2E jobs: 10 passed both the test and Core #16498 at CLI #668 remains at Maintainer actions: (1) review/merge the independent discovery workflow fix and obtain genuine runtime-branch E2E evidence; (2) review/merge CLI #668 and Core #16492/#16496, then release the CLI clock support and an updater containing both runtime fixes; (3) run Cache One for Review-routing correction: REST The later individual requests for The matching local fixture caches are retained; official Cache One artifacts have not been replaced. Corrected recording and release evidence. |
myevolve
left a comment
There was a problem hiding this comment.
Independent AI-assisted technical review
Reviewed aeed1cf2ffe310b228b69cc493de09182455372f with the independent fixture/workflow reviewer. No actionable introduced fixture defect was identified. The original job inputs, source commits, ignore caps, groups, experiments, and existing recorded clocks were preserved.
After fixing the Core review findings, the parent replayed all three fixtures using CLI 49b4c7532aa9fbeb59b300432713bd1b5ed859ea and combined Core sources including cooldown 50d4e42 and policy 683673c. All complete output YAMLs were byte-identical to this unchanged fixture head:
| Suite | SHA-256 |
|---|---|
| npm | 5f9849ddaa628895b868e0a91972b4ddf650adcea30d39f5ab8eb4201d68435f |
| group-rules | 0ca635d2ec8d6360d5b90f205ebf3f11e305d6beb8abf0a9f02fc6a2054dd357 |
| group-semver | 91b4c9b7df3a649884628a7e7222b1eced3f4b6a9213ca3796d1be7b64b102d5 |
No expectations were weakened. npm/rules retain their follow-redirects/form-data caps; the semver fixture's uncapped updates remain intentional.
This is an explicitly AI-authored technical COMMENT, not maintainer approval. The PR remains draft pending the Core/CLI release and matching upstream-cache gates; local replay is not proof that those gates are complete.
Dependent fixture migration
Regenerate the three npm fixtures discussed in #592 without changing their job policy or source commits. Draft until the CLI/Core prerequisites are released and the official proxy caches are refreshed.
153834ba37793c707347fcc723ce656a34045625after regen tests that have updated packages #594; resolve the overlap without restoring out-of-policy dedicated transitive PRs.recorded-at; all three previously recorded clocks are unchanged.Runtime verification
CLI: dependabot/cli#668 at
49b4c7532aa9fbeb59b300432713bd1b5ed859ea. Integrated Core runtime: dependabot/dependabot-core#16492 at97c3cac44b62df8ecf93b08f9041849e85ffa20fplus dependabot/dependabot-core#16496 at260f77e6e25e0b6cbcf00882ada974398de69a82, both incorporating main0286aa0868b1f0de1b908ce3358bbf994e5272c1. The shared notice-rendering change was exercised directly and all three complete fixture replays were repeated successfully; no npm policy guard or fixture contract changed.Updater image:
ghcr.io/dependabot/dependabot-updater-npm@sha256:4beb224504e150d978da4212e06eb390ba4abb630eeedcfc7d44b265aa1e0d1e, mounting the integrated npm, common and updater libraries.All three actual CLI tests passed, including a fresh byte-identical replay after merging v1.94.0’s container-isolation changes into CLI #668. CLI CI at this head also passed 104/104 checks, including 2/2 required checks (evidence). Final logs contain no updater ERROR lines, metadata rate-limit responses, unreadable-cache warnings, or job-error events. Fixture syntax is exercised by these actual CLI replays; the repository's yamllint configuration excludes
tests/, so its green check is not claimed as fixture lint coverage.Full-repository Sorbet passed on all three refreshed Core branches and again after the policy spec-isolation correction. Direct shared-notice rendering confirms INFO/fallback → NOTE, WARN → WARNING, ERROR → IMPORTANT. Three complete CLI replays at cooldown
97c3cac44b62df8ecf93b08f9041849e85ffa20f+ policy260f77e6e25e0b6cbcf00882ada974398de69a82are byte-identical, with 202/202, 200/200 and 249/249 cached calls, unchanged clocks and no metadata/job errors. Policy’s subsequentde4a7cb8bf466b2667fdb4b8bc5948a1061d86c2commit changes only spec isolation and its README; all mounted runtime library trees are unchanged. CLI source is unchanged; no new Go-suite run is claimed.The subsequent policy spec-isolation fix is independently verified by the existing two-example failing-before/passing-after reproducer, the complete previously failing worker (564 examples, 0 failures; seed 16904), and final-head full npm CI: 2231 examples, 0 failures, 4 existing pending. All three Core PRs passed 21/21 required checks. Optional Smoke remains non-green: cooldown scheduled no E2E after the swallowed discovery error; policy ran 13 E2E with 10 passes and 3 npm/rules/semver fixture failures; discovery ran all 97 E2E with 95 passes and Gradle/pip-compile failures. These use main fixtures/official caches, not these draft recordings. No failing assertion was weakened.
Correcting the metadata evidence
Earlier semver captures included GitHub API 403 rate-limit fallbacks despite successful jobs and byte-identical cached replay. That omitted PR metadata and truncated commit messages. Those captures are superseded, not treated as a valid baseline.
The corrected recording uses fresh HTTP captures and real public metadata responses. Missing metadata was fetched with trusted, authenticated
gh apiGETs and cached; healthy responses from the other two fresh captures were reused. The write-enabled host credential was never supplied to the updater or proxy. The updater generated all corrected text; no expected text, versions, clocks or policies were hand-pinned. Final matching caches are retained locally, not represented as refreshed upstream artifacts.The npm/rules jobs still ignore follow-redirects >1.15.11 and form-data >4.0.5 and reject those unsafe dedicated updates. Semver has no such caps and still records the allowed 1.16.1 / 4.0.6 updates. Old official caches mix stale full registry metadata with newer compact npm metadata, so they must be replaced rather than reused.
Landing gates
@latest(currently v1.94.0, which still drops the recorded clock).aeed1cf2ffe310b228b69cc493de09182455372ffornpm,npm-group-rules, andnpm-group-semver, using read-only GitHub authentication and checking metadata-fetch logs.No workflow bypasses, raised ignore caps, changed source commits, or hand-edited expected versions are included. The currently released toolchain is not claimed compatible with these recordings.
Independent AI review follow-up
The fixture head remains
aeed1cf2ffe310b228b69cc493de09182455372f. After review fixes at Core cooldown50d4e42and policy683673c, all three complete generated fixture YAMLs again match byte-for-byte using CLI49b4c75; inputs and expected outputs were not weakened. Independent AI review and output hashes. This supersedes the earlier runtime-source pins, not the existing release/upstream-cache gates. The PR remains draft; AI review is not maintainer approval.