Skip to content

chore(deps): update OmniNode-ai/omnibase_core/.github/workflows/occ-preflight.yml requirement to de01ec0964a2e666d739835b02957ae0f06d6a25 - #2522

Merged
jonahgabriel merged 1 commit into
devfrom
dependabot/github_actions/OmniNode-ai/omnibase_core/dot-github/workflows/occ-preflight.yml-de01ec0964a2e666d739835b02957ae0f06d6a25
Jul 28, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
dependabot/github_actions/OmniNode-ai/omnibase_core/dot-github/workflows/occ-preflight.yml-de01ec0964a2e666d739835b02957ae0f06d6a25

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on OmniNode-ai/omnibase_core/.github/workflows/occ-preflight.yml to permit the latest version.

Changelog

Sourced from OmniNode-ai/omnibase_core/.github/workflows/occ-preflight.yml's changelog.

v0.46.0 (2026-06-25)

Breaking Changes

  • bump omnibase_core to v0.46.0 — RuntimeLocal relocated from omnibase_infra into omnibase_core (runtime is now core-resident); runtime protocols are core-resident rather than spi (avoids a core->spi circular dependency); and node configuration migrates from environment-variable reads to contract + overlay resolution. Minor bump per pre-1.0 semver convention for breaking surface relocations and the env->contract config migration.

v0.45.0 (2026-06-17)

Breaking Changes

  • refactor bump omnibase_core to v0.45.0 — removes ModelOnexEnvelope public API (deleted in #1250, B4). Canonical envelope is ModelEventEnvelope[T]. Minor bump per pre-1.0 semver convention for a breaking public-API deletion.

v0.44.2 (2026-06-07)

Changes

  • chore(release) bump omnibase_core to v0.44.2 (#1217)
  • release promote dev integration to main (#1216)

v0.44.1 (2026-06-07)

Changes

  • chore(release) bump omnibase_core to v0.44.1 (#1213)
  • release promote core dev lane to main (#1211)

v0.44.0 (2026-06-06)

Features

  • feat skill-dispatch receipt-mode validator (Phase 4b) (#1237)
  • feat minimal content-addressed ArtifactStore slice (Phase 1) (#1236)
  • feat ModelArtifactRef + ModelSkillResult[T] typed receipt models (#1235)
  • feat url-authority ratchet gate — ValidatorUrlAuthority (#1232)
  • feat transport-mock lint validator — bare AsyncMock/MagicMock on EventBus/transport surfaces (#1231)
  • feat protocol-conformance tests per Protocol + portable _rel_path baseline fix (#1234)
  • feat runtime-profile registry + unregistered/no-consumer-lane validator rules (#1229)
  • feat single transport-envelope unwrap predicate + dispatch-surface test gate (#1228)
  • feat add Bifrost logical secret refs (#1223)
  • feat receipt-honesty validator — fail gamed DoD receipts (#1219)
  • feat add demo-path topic coherence gate as pre-commit + required CI (#1218)

Bug Fixes

  • fix hard-fail on contract_sha256=None in OCC eligibility validator (#1233)
  • fix reject typing.Protocol handler targets in ServiceHandlerResolver (#1230)
  • fix raise generation retry budget (#1221)

CI

  • ci wire receipt-honesty CI + pre-commit gate (queue-safe prep) (#1222)

v0.43.0 (2026-05-31)

Features

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…reflight.yml requirement to de01ec0964a2e666d739835b02957ae0f06d6a25

Updates the requirements on [OmniNode-ai/omnibase_core/.github/workflows/occ-preflight.yml](https://github.com/omninode-ai/omnibase_core) to permit the latest version.
- [Release notes](https://github.com/omninode-ai/omnibase_core/releases)
- [Changelog](https://github.com/OmniNode-ai/omnibase_core/blob/dev/CHANGELOG.md)
- [Commits](https://github.com/omninode-ai/omnibase_core/commits/de01ec0964a2e666d739835b02957ae0f06d6a25)

---
updated-dependencies:
- dependency-name: OmniNode-ai/omnibase_core/.github/workflows/occ-preflight.yml
  dependency-version: de01ec0964a2e666d739835b02957ae0f06d6a25
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Blocking findings (critical): 0
Total findings: 0
Models succeeded: none

Note: All reviewer models failed or were unavailable. Degraded results are informational during the pilot phase (OMN-8468/OMN-8524) and do not block merge. Error: all review endpoints [192.168.86.201:8000 192.168.86.201:8001 ] unreachable — preflight short-circuit (no models available)


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

@jonahgabriel
jonahgabriel merged commit 873cf49 into dev Jul 28, 2026
93 checks passed
@jonahgabriel
jonahgabriel deleted the dependabot/github_actions/OmniNode-ai/omnibase_core/dot-github/workflows/occ-preflight.yml-de01ec0964a2e666d739835b02957ae0f06d6a25 branch July 28, 2026 06:20
jonahgabriel added a commit that referenced this pull request Jul 30, 2026
… PR author (#2574)

OMN-15496 (#2569, merged 2026-07-30T18:14:35Z) made CI Summary assert 17
cross-workflow contexts fail-closed. One of them, "gate / CodeRabbit Thread
Check", is structurally absent on Dependabot PRs: cr-thread-gate-caller.yml
skips the caller job when github.actor == dependabot[bot], and because the
context is the caller-job/reusable-job form, the inner job never materialises
so NO check-run is created. Absent burns the 90 min poll deadline and then
fails closed against the SOLE required context on infra dev.

The OMN-15496 seed measured this context 16/16 present over #2546-#2567 -- a
window containing no Dependabot PR, which is how a 16/16 context can still be
absent in production.

Fixed consumer-side via a declared ACTOR_CONDITIONAL_CONTEXTS registry, not by
removing the producer skip: OMN-10276 took the producer route on omnimemory,
but omnimemory calls a LOCAL reusable and passes no secrets, whereas this
caller invokes omniclaude reusable with secrets: CROSS_REPO_PAT. Dependabot
pull_request runs do not receive regular repo secrets, so dropping the skip
here risks trading an absent-wedge for a red-wedge.

This is an applicability rule, not a bypass: the context stays fail-closed for
every author not named in the registry, and a missing --pr-author drops
nothing.

RED-before/GREEN-after on the real #2522 payload (98 unedited check-run rows):
pre-change gate -> PENDING (deadline FAILURE) naming the CR context;
post-change with dependabot[bot] -> SUCCESS; post-change with jonahgabriel ->
still PENDING. Replaying the whole Dependabot batch #2515-#2522 at merge time:
5/8 blocked before, 2/8 after, and both survivors are genuine URL Authority
Gate reds that are correctly preserved -- zero residual blocks attributable to
the CR context.

Bound in ci.yml in the same change (--pr-author), pinned by a test.

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
github-actions Bot pushed a commit that referenced this pull request Aug 29, 2026
Operator ruling 2026-08-29: "remove completely." CodeRabbit is removed
entirely, not demoted to advisory.

- delete .github/workflows/cr-thread-gate.yml and cr-thread-gate-caller.yml
- drop "gate / CodeRabbit Thread Check" from EXPECTED_EXTERNAL_CONTEXTS
  (scripts/ci/ci_summary_gate.py). infra dev requires exactly ["CI Summary"],
  so this umbrella WAS the enforcement surface here -- there was no branch
  protection entry to remove.
- ACTOR_CONDITIONAL_CONTEXTS is now empty by construction: its only entry was
  this gate (OMN-15532). The MECHANISM is retained, and so are its tests --
  re-anchored onto a synthetic registry entry over the same real Dependabot
  #2522 payload with one asserted context deleted to stand in for the absent
  case. AC1/AC2/AC3 keep their meaning; AC3 now falsifies against the shipped
  empty registry. A test that only asserted "the registry is empty" would let
  the mechanism rot until the next actor-scoped producer wedged a lane.
- drop the OMN-15815 concurrency-group property test, which existed solely
  for cr-thread-gate-caller.yml; leave a note describing the template shape
  that should bring it back.
- refresh prose in ci.yml, call-receipt-gate.yml, auto-merge.yml and the
  required-context probe that cited the deleted workflow or claimed the
  context is live on core/market/claude dev (it is not, as of today).

Historical provenance comments in unrelated tests/docs (CodeRabbit findings
that produced a regression guard) are deliberately left intact.

Local: uv run pytest tests/ci/test_ci_summary_gate.py -q -> 84 passed;
tests/ci/test_ci_workflow_resilience.py + test_workflow_uses_refs_resolve.py
+ tests/unit/scripts/test_omninode_ci_required_context_probe.py -> 74 passed;
ruff format/check clean; mypy --strict clean on ci_summary_gate.py.

Ref: OMN-16933
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant