chore(deps): bump google-cloud-resource-manager from 1.17.0 to 1.18.0 - #1103
chore(deps): bump google-cloud-resource-manager from 1.17.0 to 1.18.0#1103dependabot[bot] wants to merge 1 commit into
Conversation
5150bc0 to
ccba3d2
Compare
|
Exact-current-head review request for |
ccba3d2 to
d94c3c5
Compare
|
Rebased onto current |
d94c3c5 to
30b83ee
Compare
|
Current-head rebase published at |
3cb3a95 to
0bec018
Compare
|
Rebased Dependabot update onto current main@c47bee59. Exact head: 0bec018. Current diff was checked for path integrity; required workflow YAML updates were actionlint-validated where applicable, and hash-lock changes retain explicit package/file digests. |
|
Rebased Dependabot update onto current main@c47bee59. Exact head: 0bec018. Current diff was checked for path integrity and explicit hash-lock integrity. |
0bec018 to
d76211d
Compare
|
@opencode-agent review exact current head |
|
@opencode-agent Please review exact current HEAD |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
622de4f2e6b04c9c846985a2d09ec8b8e196d176. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- CodeQL PR/CodeQL compatibility analysis (actions): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587957)
- CodeQL PR/CodeQL compatibility analysis (python): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999588012)
- CodeQL PR/CodeQL merge preview (actions): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587961)
- CodeQL PR/CodeQL merge preview (python): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587968)
- CodeQL compatibility analysis (actions) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587957)
- CodeQL compatibility analysis (python) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999588012)
- CodeQL merge preview (actions) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587961)
- CodeQL merge preview (python) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807358/job/96999587968)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807355/job/96999579669)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/32559807355/job/96999579669)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
R1 --> V1["required checks"]
OpenCode Review Overview
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
R1 --> V1["required checks"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head bounded evidence and found no blocking issues.
Findings
No blocking findings.
Summary
Inspected changed file requirements-strix-ci-hashes.txt (focused hunk @@ -723,27 +723,27 @@): the version line moves atomically to 1.18.0 together with both replacement --hash=sha256 digests and retains the '# via google-cloud-aiplatform' annotation; diff stat confines the change to 3 insertions/3 deletions in this single file. Approval sufficiency: sufficient for a hash-only lock refresh with no supported source files changed. Verification posture: trusted current-head evidence only; no model-executed commands. Linter/static: no linter contract applies to a pip hash-lock file; hadolint/npm audit/bandit/trivy targets are untouched. TDD/regression: not applicable to generated lock content; repository convention verified via changed-file history showing identical mechanical updates (d76211d, eb0ee5c). Coverage: Coverage execution evidence Result PASS with test coverage not applicable because no supported changed source files or package manifests were found. Docstring coverage: Coverage execution evidence marks docstring coverage not applicable because no supported changed source files or package manifests were found. DAG: CodeGraph-backed flowchart maps requirements-strix-ci-hashes.txt:735 to the hash-pinned Strix CI install path; reflects head-to-base changed flow only. PoC/execution: no OPENCODE_EXECUTION_RECEIPT present; verdict rests on trusted diff/diff-stat/check traces, stated as a source limitation. DDD/domain: no domain logic touched. CDD/context: lockfile belongs to the Strix CI dependency context; no cross-context coupling. Similar issues: prior Dependabot bumps of the same file merged with the same shape. Claim/concept check: PR title/body claim (bump 1.17.0 -> 1.18.0) matches the diff exactly; Dependabot release-note excerpt treated as untrusted metadata. Standards search: no external standard material to the change; pip --require-hashes semantics confirmed from the file's own pinned-hash format. Compatibility/convention: naming/reserved-word review not applicable — no new tables, columns, API fields, routes, or identifiers introduced; file follows existing lockfile convention. Breaking-change/backcompat: minor-version transitive bump consumed only through the pinned lock; no public API surface changed. Implementation completeness: complete — no placeholder bodies or TODO branches in the changed surface. Performance: negligible; install-time resolution only. Developer experience: DX surface is CI dependency maintenance; evidence used is the diff-stat confinement and unchanged test/security command contracts in Review execution contracts. User experience: UX surface is none beyond CI runtime; end-user surfaces untouched. Visual/DOM: non-web interaction surface reviewed (packaging/lockfile); no web UI changed. Accessibility/i18n: not applicable — no UI or text surfaces changed. Supply-chain/license: hashes are explicit sha256 pins for both distributions, preserving the hash-locked supply-chain posture; license set unchanged by this context's existing google-cloud family. Packaging: packaging contract intact; unpackaged_source_surfaces is empty and pyproject-based contracts are untouched. Security/privacy: no secrets, identifiers, or trust boundaries touched; hash pinning strengthens rather than weakens integrity controls.
Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including requirements-strix-ci-hashes.txt.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects requirements-strix-ci-hashes.txt to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source claims require trusted bounded source evidence prepared outside the isolated model process; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: deterministic repair does not infer browser runtime execution; source-backed DOM/UI evidence and trusted workflow receipts were reviewed when present, and non-web surfaces used API/CLI/log/docs/workflow evidence instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.
Adversarial validation
{"status":"passed","probes":[{"path":"requirements-strix-ci-hashes.txt","line":735,"hypothesis":"The bump produced a malformed or partial hash-lock pin: version advanced to 1.18.0 without matching sha256 digests, which would make the next hash-verified install fail resolution.","attack_or_counterexample":"Boundary attack treating the hunk as three independently editable lines: install with --require-hashes against an entry whose version and digest lines diverged, or a stale 1.17.0 reference left behind.","evidence":"Trusted focused-changed-hunks diff trace at requirements-strix-ci-hashes.txt:735 observed the line change atomically from 'google-cloud-resource-manager==1.17.0 \\' to 'google-cloud-resource-manager==1.18.0 \\' together with both replacement --hash=sha256 lines at :736-:737 and retention of the '# via google-cloud-aiplatform' annotation, so the partial-pin counterexample cannot be constructed from this diff; Trusted current-head source binding at requirements-strix-ci-hashes.txt:735; source-line-sha256=bb283f1a53e442d4cb3543177e2dfea65fdf191091b4682e855d47e50013ba35","outcome":"falsified"},{"path":"requirements-strix-ci-hashes.txt","line":737,"hypothesis":"The isolated transitive bump desynchronized the lock snapshot from its consumers or regressed CI, leaving broken or failing installs at this head.","attack_or_counterexample":"Stale-state attack: assume leftover 1.17.0 entries elsewhere in the lock or failed required checks at head 3b58d8e8d5db29c623bf90ee42ba1b54a7a58749 contradicting a clean bump.","evidence":"Trusted diff-stat and Failed GitHub Check trace at requirements-strix-ci-hashes.txt:737 observed 'requirements-strix-ci-hashes.txt | 6 +++---' confining all edits to the single resource-manager entry (both old hash lines removed at :735-:737 scope), Changed files listing only this file, and 'No completed failed GitHub Checks were present when evidence was collected' for this head, rejecting the desync/regression hypothesis; Trusted current-head source binding at requirements-strix-ci-hashes.txt:737; source-line-sha256=123e98ad4fcc4d167ec32950037a8d65f05fab152726ff0a13561ba97c58e531","outcome":"falsified"}],"residual_risk":"Residual risk is limited to upstream supply-chain trust in the two new sha256 digests themselves: the workflow provided no independent PyPI re-download verification receipt for google-cloud-resource-manager==1.18.0 inside this run, and no CI install of the refreshed lock was executed within the model process. Both risks are bounded because the entry keeps explicit dual-digest pinning and current-head checks report no failures."}- Result: APPROVE
- Reason: Dependency-only hash-lock bump of google-cloud-resource-manager 1.17.0 -> 1.18.0 in requirements-strix-ci-hashes.txt; both adversarial probes (malformed partial pin, lock desync/CI regression) were falsified against trusted current-head diff, diff-stat, and check evidence.
- Head SHA:
3b58d8e8d5db29c623bf90ee42ba1b54a7a58749 - Workflow run: 32596393246
- Workflow attempt: 1
3b58d8e to
ea3b686
Compare
|
The branch was rebased onto current protected |
Bumps [google-cloud-resource-manager](https://github.com/googleapis/google-cloud-python) from 1.17.0 to 1.18.0. - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-resource-manager-v1.17.0...google-cloud-resource-manager-v1.18.0) --- updated-dependencies: - dependency-name: google-cloud-resource-manager dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
ea3b686 to
6c8118c
Compare
Exact-head lock verification
|
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head bounded evidence and found no blocking issues.
Findings
No blocking findings.
Summary
Approval sufficiency: Hash-pinned lockfile update of a single transitive dependency (1 file, 3 insertions(+), 3 deletions(-)); mergeable and clean. Verification posture: 2 adversarial probes falsified (supply-chain hash integrity, dependency compatibility); no failed GitHub checks; no unresolved threads. Linter/static: N/A — lockfile-only change, no source files. TDD/regression: N/A — no source or test files changed; diff stat confirms 1 file, 3+/3-. Coverage: PASS — not applicable (no supported changed source files or package manifests), per Coverage execution evidence. Docstring coverage: not applicable — no supported changed source files or package manifests, per Coverage execution evidence. DAG: No code flow change; lockfile-only dependency update; Blast radius: test symbols only (CodeGraph). PoC/execution: Documented uv materialization command reproduced at both versions (1.17.0 and 1.18.0) per exact-head conversation evidence. DDD/domain: N/A. CDD/context: Dependabot automated lock-only bump; consistent with 5 prior Dependabot bumps in file history. Similar issues: None — prior Dependabot bumps in this file were lock-only with no regressions. Claim/concept check: PR body version 1.18.0 matches diff; both hashes are valid 64-char SHA256 hex strings; # via google-cloud-aiplatform annotation unchanged. Standards search: Semver minor bump is backward-compatible by contract; hash-pinned requirements prevent supply-chain tampering. Compatibility/convention: Backward-compatible minor bump; hash format and # via convention match existing entries; no naming or reserved-word concerns. Breaking-change/backcompat: No breaking changes (semver minor only). Performance: N/A — lock file change only. Developer experience: Lock verified by documented uv command reproduction; hash-pinning convention maintained; Dependabot branch current with protected main. User experience: N/A — CI-only dependency. Visual/DOM: N/A — no UI changes. Accessibility/i18n: N/A — no UI changes. Supply-chain/license: Hash-pinned format prevents artifact substitution; both hashes valid SHA256; google-cloud-resource-manager from googleapis/google-cloud-python (official source); no license changes. Packaging: requirements-strix-ci-hashes.txt is a hash-pinned lockfile following pip --require-hashes convention. Security/privacy: No secrets, no API changes, no PII; hash verification prevents supply-chain attacks; no network-accessible surfaces changed.
Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including requirements-strix-ci-hashes.txt.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects requirements-strix-ci-hashes.txt to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source claims require trusted bounded source evidence prepared outside the isolated model process; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: deterministic repair does not infer browser runtime execution; source-backed DOM/UI evidence and trusted workflow receipts were reviewed when present, and non-web surfaces used API/CLI/log/docs/workflow evidence instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.
Adversarial validation
{"status":"passed","probes":[{"path":"requirements-strix-ci-hashes.txt","line":735,"hypothesis":"The new SHA256 hashes for google-cloud-resource-manager==1.18.0 might not correspond to legitimate PyPI-published artifacts, enabling a supply-chain attack with tampered hashes that execute arbitrary code in CI.","attack_or_counterexample":"An attacker could replace legitimate package hashes with hashes pointing to a compromised wheel/sdist of google-cloud-resource-manager==1.18.0; without hash verification, pip would install the tampered artifact and execute attacker-controlled code during CI materialization.","evidence":"Focused changed hunk (Diff stat: 1 file changed, 3 insertions(+), 3 deletions(-)) shows the google-cloud-resource-manager entry updated from 1.17.0 to 1.18.0 with two new SHA256 hashes spanning requirements-strix-ci-hashes.txt:735 and :737. The hash-pinned format (pip --require-hhashes) verifies the downloaded PyPI artifact against these hashes, making hash substitution impossible — pip rejects installation if the artifact checksum does not match. Conversation evidence (@seonghobae 2026-08-24T09:50:51Z) states: Reproduced the repository documented uv command for the isolated dependency at both versions. Failed GitHub Check evidence: No completed failed GitHub Checks were present when evidence was collected. Coverage execution evidence: PASS (not applicable). Trusted current-head source binding at requirements-strix-ci-hashes.txt:735; source-line-sha256=bb283f1a53e442d4cb3543177e2dfea65fdf191091b4682e855d47e50013ba35","outcome":"falsified"},{"path":"requirements-strix-ci-hashes.txt","line":737,"hypothesis":"The minor version bump of google-cloud-resource-manager from 1.17.0 to 1.18.0 could introduce a breaking API change or incompatibility that breaks the CI pipeline consuming it transitively via google-cloud-aiplatform==1.133.0.","attack_or_counterexample":"A semver-minor release could remove deprecated APIs, change method signatures, or alter return types that the Strix CI tooling depends on through google-cloud-aiplatform, causing runtime failures when the lockfile is materialized.","evidence":"Diff stat (1 file changed, 3+/3-) confirms only the google-cloud-resource-manager==1.18.0 entry is modified; no other hashes in the lock file changed. The second hash at requirements-starry-ci-hashes.txt:737 is a valid 64-character SHA256 hex string. Semver minor version bump (1.17.0 -> 1.18.0) is backward-compatible by contract. The # via google-cloud-aiplatform annotation is unchanged. Conversation evidence (@seonghobae 2026-08-24T09:50:51Z) confirms documented uv materialization was reproduced at both versions. Failed GitHub Check evidence: No completed failed GitHub Checks were present. Coverage: PASS. Trusted current-head source binding at requirements-strix-ci-hashes.txt:737; source-line-sha256=123e98ad4fcc4d167ec32950037a8d65f05fab152726ff0a13561ba97c58e531","outcome":"falsified"}],"residual_risk":"Minimal residual risk. The hash-pinned lockfile and pip --require-hashes model prevent artifact substitution, and the semver-minor bump is backward-compatible by contract. The isolated review environment lacked network access to independently verify PyPI artifact hashes, but the trusted workflow reproduced the documented uv materialization command at both versions (1.17.0 and 1.18.0), providing external verification. No failed GitHub checks or unresolved threads corroborated any issue."}- Result: APPROVE
- Reason: Hash-pinned lockfile bump of google-cloud-resource-manager 1.17.0->1.18.0 in requirements-strix-ci-hashes.txt; no failed GitHub checks, no unresolved threads, no source or test files changed, uv materialization reproduced at both versions
- Head SHA:
6c8118cb46cbac9c974c9b7ffff53cbbc9ac3b19 - Workflow run: 32730473552
- Workflow attempt: 1
|
Scheduler run Current GitHub This comment is not OpenCode approval and not merge evidence. |
Bumps google-cloud-resource-manager from 1.17.0 to 1.18.0.
Release notes
Sourced from google-cloud-resource-manager's releases.
Commits
a5ad18cchore: release main (#17482)f6937b3chore(main): release google-cloud-bigtable 2.39.0 (#17497)172302bci(bigquery-storage): fixcore_deps_from_sourceandprerelease_depsby in...e726878fix(bigframes): world-readable temp zip in create_cloud_function (#17522)2f893b1fix: bump@angular/common,@angular/forms,@angular/platform-browserand@ang...f23063ffix: bump langsmith from 0.8.0 to 0.8.18 in /packages/bigframes (#17518)6fc45e3fix: bump undici and@angular/buildin /packages/bigframes/bigframes/display/...36b5b7efix: bump msgpack from 1.1.1 to 1.2.1 in /packages/bigframes (#17520)11de939tests: add Python 3.15 pre-release testing (#17517)0258405fix(bigquery): close GAPIC storage transport and auth sessions to prevent soc...