Repository navigation
Conversation
myevolve
left a comment
There was a problem hiding this comment.
Independent AI-assisted technical review
Reviewed ddcf3e24cea11fcd30a7e8de4b2f62d5278b6421 with a separate fixture/workflow reviewer. No actionable introduced defect was identified. Original job inputs, source commits, primary version selections, and expected event contracts were preserved; the generated Hibernate release metadata and uncapped pycparser transitive result were not hand-pinned to stale cache contents.
Existing runtime evidence at this unchanged head (not rerun by the review agent): the unchanged Cache One workflow passed for Gradle and pip-compile. Downloaded artifacts replayed with released CLI 1.94.0, full byte-identical YAML, and 119/119 and 130/130 cached calls.
A direct upstream gh workflow run cache-one.yml attempt returned HTTP 403: Must have admin rights to Repository. Fork artifacts are not upstream cache publication; the stale upstream Gradle check is still a real failure.
This is an explicitly AI-authored technical COMMENT, not maintainer approval. Upstream cache publication and required maintainer approval remain external gates.
|
pycparser 3.11 was released on 2026-10-09, so this needs |
Summary
Refresh the Gradle and pip-compile recordings after diagnosing the two remaining failures in Core Smoke run 37818658609 (95/97 E2E jobs passed).
pycparser==3.1, rather than 3.0.Both complete fixtures equal actual CLI-generated output. All original input fields, pinned source commits, ignore conditions and expected event sets are unchanged. No Core/proxy code, cache-key policy, workflow assertions or npm fixtures changed. This is independent of #593 and does not require the unreleased CLI clock feature.
Root cause and evidence
The original caches came from run 37309245577:
cache-gradleartifact 11344887698 andcache-python-pip-compileartifact 11344573838.:443port. Current requests use that port and miss the old keys. The failing CI job reached live Maven 404s and omitted all four expected PRs (95/125 calls cached). A local baseline reached live 200s and matched the old fixture, but only 75/116 calls were cached. Warming that cache restored a byte-identical 116/116-cached replay of the old fixture. A separate empty-cache recording then exposed the additional legitimate Hibernate release notes captured here.Cache-Control: max-age=0; the current request omits that header. Hashing the same Accept value with/without Cache-Control reproduces the oldc9790a025c1b…and newdb00c559751e…keys exactly. The miss reaches the live index and selects pycparser 3.1. The source lockfile omits the argon2/cffi/pycparser chain requested bydjango[argon2], so native pip-compile legitimately resolves these new, unpinned dependencies. Both CI and the original-cache local baseline fail with exactly the same five 3.0 → 3.1 changes (96/130 calls cached). A separate empty-cache recording produces exactly the same regenerated fixture.No resolver failure was demonstrated that warrants changing Core. Broadening ignore conditions, dropping PR expectations, or normalizing proxy keys would not be a justified fix for these recordings.
Verification
Actual released CLI v1.94.0, with the published Core-main
0286aa0868b1f0de1b908ce3358bbf994e5272c1updater images and the unmodified CI proxy:smoke-gradle.yamlsmoke-python-pip-compile.yamlNo metadata/job errors, missing cache bodies, HTTP 403s or HTTP 429s in either final replay. No host GitHub/job/OIDC credentials were forwarded to updater containers. Final captures were made from empty cache directories, not by editing cached responses.
Pinned images:
ghcr.io/dependabot/dependabot-updater-gradle@sha256:fbd707ca255d913da710a1038bc6edfae548c0274253bb2330ec0165d02a5488ghcr.io/dependabot/dependabot-updater-pip@sha256:da5b3474c71ce9ed8bcd253e9be0f5d886139bf1e43914a2ba1620d528044972ghcr.io/dependabot/proxy@sha256:a39e7ef7188c9a4b36692df47a0e8f876e83199e657cd0b6be00e736fbe03c2f(commit20763b13426c928305a465bbada1fde7a88104fe)Fixture SHA-256s:
13d35a825dce1a53f08d2efeeaabf2e705105e6a93fde4f1ddaaa77f980d1efcb3161ea2ee5febb3022378a79eed7ef0b833745352be0b95b8c971ebef232225Released CI at ddcf3e2
Run 37840899141 used the same updater/proxy image contents as the local proof (registry manifest config digests checked against the job logs). pip-compile PASS with an identical diff result, but only 96/130 calls cached. Gradle FAIL at 75/116 cached: all four expected PRs were created, and the entire diff is the missing 29-line Hibernate release-note block. The job explicitly replayed the old cached 200 response for
hibernate/hibernate-orm/releases?per_page=100. This is the documented stale-metadata cache gate, not a reason to delete those genuine expectations. Suite discovery and yamllint also pass.The verified matching local cache archive is
gradle-pip-replay-caches-ddcf3e2.tar.gz, SHA-256691a966dd96f7346ee295d48abe6bdae8c9c5851429214cdf9b155f1adeb52a9. It is not an upstream Actions artifact.Hosted clean-cache proof (fork only)
The unchanged upstream Cache One workflow now passes on GitHub-hosted Ubuntu runners for this exact head,
ddcf3e24cea11fcd30a7e8de4b2f62d5278b6421. Workflow blobc4853add0bd80f64618e6c18a2c4bc300558957cis identical in the fork and upstream. Both jobs used released CLI v1.94.0, the same updater/proxy image contents documented above, and read-only job-token permissions. No workflow, fixture or updater source was changed for these runs.The clean recordings naturally show only 54/119 and 30/130 in-run cache hits, respectively: each began with an empty directory. The downloaded artifacts were then replayed without editing their responses, producing the 100%-cached results above with no metadata/job errors. Fixture SHA-256s still match those listed above.
GitHub-reported upload SHA-256s (also recorded in each upload log):
3047ed8721a26fc4678b64e5cebc32ca6a7dfb7be2ec0170d803ad7bdcda4e7d62a47894871b19dc7de237d981b1c56a8695d53ae41d29d7888a19a758d60772Both artifacts expire 2027-01-06. Download them with:
These are fork evidence, not upstream cache publication. Core and upstream Smoke still download artifacts from
dependabot/smoke-tests. The upstream Gradle check therefore remains failed until a maintainer runs the two upstream Cache One commands below and reruns Smoke. This PR is ready for review; merging still requires the upstream cache refresh and passing Smoke checks. The temporary fork workflow was disabled after capture; all fork workflows are inactive.Maintainer landing gate
Ready for review, not ready to merge. The
dependabot/maintainersteam is already requested; no duplicate review request is needed. Local and fork-hosted green runs are not an upstream CI-green claim. The old Gradle cache does not contain the added release-note metadata, so this fixture and its cache must be refreshed together.Run Cache One in this repository at this PR's
refs/pull/595/head, once withpackage_manager=gradleand once withpackage_manager=python-pip-compile. Both runs must pass and publish their matching named artifacts.--ref mainselects the existing workflow;git-refselects the reviewed fixture checkout. These commands require upstream Actions write access.Review can proceed now. Rerun this PR's Smoke checks against the published artifacts and merge only after those checks pass and review is complete.
Rerun Core #16498 Smoke after the fixture merge so discovery uses the new fixture blobs and caches. The historical 95/97 run remains failed until replaced by actual successful CI evidence.
Contributor access is read-only upstream; the official cache workflow/merge actions need a maintainer. Existing review and release gates on the independent Core/CLI/npm work are unchanged.
Related: #592; dependabot/dependabot-core#16498; dependabot/dependabot-core#16488.