Repository navigation
chore(deps): bump omnibase-core to 0.47.18 (OMN-18595) - #3855
Conversation
Automated dependency cascade from OmniNode-ai/omnibase_core release 0.47.18. Onex-Workflow: Release Onex-Run: https://github.com/OmniNode-ai/omnibase_core/actions/runs/35463487685
…ckfile The cascade bump changes uv.lock, which is an input to the runner image's shared-env digest, so the bound identity went stale and the build-only smoke gate refused with the recomputed value. Regenerated with the command that gate's own error names. The recomputed shared-env digest matches what CI reported, and only the two derived digests move; every pinned tool version is unchanged.
|
No OCC evidence companion was minted for this PR. this PR is already bound to OCC#10457; its evidence companion exists and nothing needs authoring To clear this: Nothing to do — the companion already exists. Reported by |
|
OCC autobind did not rebind this PR. This PR's evidence-source stamp line names To clear this: Reported by |
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 0
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 5 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
uv.lock, omnibase-core package entry(glm-review) — New package hashes accepted without provenance verification | The diff swaps sdist and wheel hashes for omnibase-core 0.47.18 as generated by uv lock. No evidence in the diff or commit message indicat - [MAJOR]
uv.lock, omnibase-core dependencies block(glm-review) — Dependency list of omnibase-core unchanged across the version bump | The version bump changes only the version string and artifact URLs; thedependenciesblock (blake3, tree-sitter, etc.) is byte-id - [MAJOR]
docker/runners/runner-image.lock.json(glm-review) — No visible test or integration coverage for the bump | The diff touches only lock and config files. There are no accompanying test changes, canary runner validation, or CI job changes that exercise th - [MINOR]
pyproject.toml, dependencies and override-dependencies blocks(glm-review) — omnibase-spi and omnibase-compat pins not evaluated for compatibility | The comment in pyproject.toml references specific upstream core PRs (#1439, #1440) carried by the new release, but omnibase-spi - [MINOR]
pyproject.toml, dependencies section comment(glm-review) — Stale comment about git-rev override | The comment block referencing OMN-17802 explains why a git-rev override is not active, tied to the 0.47.17 rationale. After bumping to 0.47.18 the comment no lon
|
| Surface | Meaning | Blocks merge? |
|---|---|---|
| Review threads | Per-finding, posted by the reviewer | No (informational) |
Hostile Review Thread Gate |
Deterministic: unresolved hostile-reviewer threads exist | Fails until resolved (not yet a required context) |
degraded verdict |
Fewer than 2 models succeeded (infra) | No |
Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review, qwen3-review-b, glm-review (OMN-8468/OMN-8524/OMN-17492)
…ibase_infra#3855 (#10481) * evidence(OMN-18595): author OCC companion for OmniNode-ai/omnibase_infra#3855 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 2a723ca25addf4268b64233ed52957a26b25078f. * evidence(OMN-18595): self-bind OCC#10481 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai>
…47.18 Both are derived from the core pin and both were stale against the bump, so CI failed on them rather than on anything the bump broke. The fallback version matrix is regenerated by the command its own test names, scripts/update_version_matrix.py, which moves the core range to >=0.47.18,<0.48.0. The released-core seam fixture freezes the published surface infra consumes and is hand-maintained by its own update procedure, which every previous cascade bump followed; the bot-opened PR omitted it. Only the frozen version moves. The symbol and typed-field surface is unchanged and still verifies against the installed 0.47.18, which is what the seam test asserts. Focused run: tests/unit/runtime/test_seam_released_core_pin.py and tests/unit/runtime/test_fallback_matrix_sync.py, 4 passed.
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 4
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 4 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture surface unchanged across core version bump | The fixture's own update procedure requires re-running the seam test and recording the new surface only after confirming every consumer type-c - [MINOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Fixture filename diverges from pinned core version | The file is named 0.46.11_expected_symbols.json but now pins core_version 0.47.18. The filename was already stale at 0.47.17, and this diff touches - [MINOR]
docker/runners/runner-image.lock.json(glm-review) — Runner image identity digests updated without provenance | identity_digest and shared_env_digest change alongside the core bump, but image_version remains 8. If image_version gates image rebuild or ca - [MINOR]
pyproject.toml(glm-review) — No release-notes or changelog evidence for the core bump | The comment references specific upstream features tied to prior bumps (core #1439, #1440) but the 0.47.18 bump carries no analogous justifica
…8.34 The fallback matrix now requires core >=0.47.18, so the integration proof's two hardcoded versions move with it: the rejected pin becomes 0.47.17 and the accepted one 0.47.18. Without this the proof asserts the previous matrix and fails against the one this PR ships. The project version moves to 0.38.34 because this PR changes packaged source and the release-identity gate refuses new packaged bytes on an already published version; 0.38.33 published at 21:20:42Z carrying the old core pin. That release is also what omnimarket 0.4.134 needs in order to resolve at all, since no published omnibase_infra currently admits core 0.47.18. Focused run: the two integration proofs plus the two unit fixtures, 8 passed.
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 5 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture version bumped but symbol surface unchanged | The fixture exists to freeze the exact symbol surface consumed from omnibase-core and fail loudly when it drifts. The diff bumps core_version - [MAJOR]
docker/runners/runner-image.lock.json(glm-review) — Runner image lock digests regenerated without corresponding install-args or source changes | identity_digest and shared_env_digest both changed, but the only dependency change in the diff is omnibase- - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — Version matrix tests updated mechanically with no negative boundary case | The rejection test now asserts 0.47.17 is rejected and the acceptance test asserts 0.47.18 is accepted. There is no test for - [MINOR]
src/omnibase_infra/runtime/version_compatibility.py(glm-review) — Fallback matrix max_version not revisited after pin bump | min_version moved to 0.47.18 while max_version remains 0.48.0. If 0.47.x releases continue, this is fine, but the constraint allows any 0.47. - [MINOR]
tests/fixtures/seams/core_release/(glm-review) — Stale fixture filename no longer matches recorded core version | The file is named 0.46.11_expected_symbols.json but now records core_version 0.47.18. This predates the diff in origin but the diff act
….34 relock The version bump relocked uv.lock, which is an input to the runner image's shared-env digest, so the value regenerated two commits ago went stale again. This is the last lockfile-touching change on the branch, so this digest is the one that ships. Only the two derived digests move.
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 0
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 5 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture version bumped without any symbol surface change | The fixture's stated purpose is to fail loudly when the core pin moves, freezing the exact symbols and field types consumed. The diff ch - [MAJOR]
docker/runners/runner-image.lock.json(glm-review) — Unexplained digest churn in runner-image.lock.json | identity_digest and shared_env_digest both change, yet the only dependency change in the diff is omnibase-core. shared_env_install_args, uv_version - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — No test coverage for the upper bound of the fallback matrix | The matrix retains max_version 0.48.0 through three consecutive pin bumps. Tests cover rejection of the immediately previous version and a - [MINOR]
uv.lock(glm-review) — uv.lock upload timestamps dated in the future | The PyPI upload-time values for omnibase_core 0.47.17 and 0.47.18 are 2026-09-18 and 2026-09-19. These timestamps come from the registry index and canno - [MINOR]
src/omnibase_infra/runtime/version_compatibility.py(glm-review) — Triple-maintained version pin invites drift | The omnibase-core version now lives in pyproject dependencies, [tool.uv] override-dependencies, the _FALLBACK_MATRIX, the seam fixture, and uv.lock. This
…se-core-0.47.18-omn-18595 # Conflicts: # docker/runners/runner-image.lock.json
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 4
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 4 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture bumped in metadata but surface unchanged | The fixture's stated purpose is to fail loudly when the omnibase-core surface changes. The diff changes _comment and core_version to 0.47.18 but - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — Rejection test only ever exercises the immediately preceding pin | test_fallback_matrix_rejects_the_previous_core_pin is updated from 0.47.16 to 0.47.17, keeping the test perpetually one patch behind - [MINOR]
src/omnibase_infra/runtime/version_compatibility.py(glm-review) — Core pin duplicated across four sites with no drift guard visible | The 0.47.18 bump must be replicated in pyproject.toml dependencies, pyproject.toml override-dependencies, uv.lock (three locations), - [MINOR]
docker/runners/runner-image.lock.json(glm-review) — Runner image identity digests changed with no provenance in diff | identity_digest and shared_env_digest in runner-image.lock.json are both rotated. The only plausible driver in this diff is the omnib
Summary
Dependency bump triggered by the omnibase_core 0.47.18 release (tag v0.47.18, release commit 0ce46237d20d270a5a281bd389cfc17b3bda0c82).
pyproject.tomlexact pin moves fromomnibase-core==0.47.17to==0.47.18, in both dependency groups.uv.lockrelocked to match.docker/runners/runner-image.lock.jsonregenerated, becauseuv.lockis an input to the runner image's shared-env digest and the build-only smoke gate refuses a stale one. Only the two derived digests move; every pinned tool version is unchanged.Head commit 2a723ca, unchanged from the pull request this replaces.
Why this replaces #3851
#3851 carried the same branch and the same head. It was opened by the cascade citing the upstream release's change-control companion, which is the cascade convention, but that companion predates this change and therefore predates this change's own evidence, so the preflight resolved a change-control tree in which that evidence could not exist and reported a ticket mismatch. Correcting the citation in place was not reachable: one guard refuses an edit that removes an existing citation, the receipt gate refuses a body carrying two, the resolver reads the first, and the receipt gate's own fenced-stamp remedy is refused by the guard as well. That defect is filed as OMN-18853 and is deliberately not fixed here. Opening a replacement whose citation is correct from the start avoids disabling any gate. Nothing about the code changed.
Evidence
This change's own autobind companion, 10457, merged as 6f1bcf306e31d9d191b9cbbbb8931aa670256d3d. No evidence was hand-authored, because correct evidence already existed and only the citation was wrong: that companion carries the receipts for this exact change, both PASS, bound to commit 1c10552, which is a commit of this pull request.
Its probe is content-bound rather than an existence check, and I re-ran both halves live against the GitHub contents API rather than trusting the recorded result. The published core 0.47.18 artifact URL is present in the lockfile once at the receipt-bound commit and once at the current head, exit 0 in both cases, and absent at the merge base fa47e3a, exit 1. That is a real red-green pair.
What this unblocks
omnimarket 0.4.134 currently cannot publish: it declares a core floor of 0.47.18 while every published omnibase_infra pins core to 0.47.16 or 0.47.17, so the dependency graph is unsatisfiable and the pin-resolvability gate has failed on three consecutive omnimarket merges. Landing this pin and then cutting an omnibase_infra release resolves it. v0.38.33 does not, having been cut from a dev that still carried the old pin.
Evidence-Ticket: OMN-18595
Evidence-Source: OCC#10457