Skip to content

chore(deps): bump omnibase-core to 0.47.18 (OMN-18595) - #3855

Merged
jonahgabriel merged 6 commits into
devfrom
automation/bump-omnibase-core-0.47.18-omn-18595
Sep 19, 2026
Merged

jonahgabriel merged 6 commits into
devfrom
automation/bump-omnibase-core-0.47.18-omn-18595

Conversation

@jonahgabriel

Copy link
Copy Markdown
Collaborator

Summary

Dependency bump triggered by the omnibase_core 0.47.18 release (tag v0.47.18, release commit 0ce46237d20d270a5a281bd389cfc17b3bda0c82).

  • pyproject.toml exact pin moves from omnibase-core==0.47.17 to ==0.47.18, in both dependency groups.
  • uv.lock relocked to match.
  • docker/runners/runner-image.lock.json regenerated, because uv.lock is an input to the runner image's shared-env digest and the build-only smoke gate refuses a stale one. Only the two derived digests move; every pinned tool version is unchanged.

Head commit 2a723ca, unchanged from the pull request this replaces.

Why this replaces #3851

#3851 carried the same branch and the same head. It was opened by the cascade citing the upstream release's change-control companion, which is the cascade convention, but that companion predates this change and therefore predates this change's own evidence, so the preflight resolved a change-control tree in which that evidence could not exist and reported a ticket mismatch. Correcting the citation in place was not reachable: one guard refuses an edit that removes an existing citation, the receipt gate refuses a body carrying two, the resolver reads the first, and the receipt gate's own fenced-stamp remedy is refused by the guard as well. That defect is filed as OMN-18853 and is deliberately not fixed here. Opening a replacement whose citation is correct from the start avoids disabling any gate. Nothing about the code changed.

Evidence

This change's own autobind companion, 10457, merged as 6f1bcf306e31d9d191b9cbbbb8931aa670256d3d. No evidence was hand-authored, because correct evidence already existed and only the citation was wrong: that companion carries the receipts for this exact change, both PASS, bound to commit 1c10552, which is a commit of this pull request.

Its probe is content-bound rather than an existence check, and I re-ran both halves live against the GitHub contents API rather than trusting the recorded result. The published core 0.47.18 artifact URL is present in the lockfile once at the receipt-bound commit and once at the current head, exit 0 in both cases, and absent at the merge base fa47e3a, exit 1. That is a real red-green pair.

What this unblocks

omnimarket 0.4.134 currently cannot publish: it declares a core floor of 0.47.18 while every published omnibase_infra pins core to 0.47.16 or 0.47.17, so the dependency graph is unsatisfiable and the pin-resolvability gate has failed on three consecutive omnimarket merges. Landing this pin and then cutting an omnibase_infra release resolves it. v0.38.33 does not, having been cut from a dev that still carried the old pin.

Evidence-Ticket: OMN-18595
Evidence-Source: OCC#10457

onexbot-occ-writer Bot and others added 2 commits September 19, 2026 19:11
Automated dependency cascade from OmniNode-ai/omnibase_core release 0.47.18.

Onex-Workflow: Release
Onex-Run: https://github.com/OmniNode-ai/omnibase_core/actions/runs/35463487685
…ckfile

The cascade bump changes uv.lock, which is an input to the runner image's
shared-env digest, so the bound identity went stale and the build-only smoke
gate refused with the recomputed value.

Regenerated with the command that gate's own error names. The recomputed
shared-env digest matches what CI reported, and only the two derived digests
move; every pinned tool version is unchanged.
@jonahgabriel
jonahgabriel enabled auto-merge (squash) September 19, 2026 21:27
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

No OCC evidence companion was minted for this PR.

this PR is already bound to OCC#10457; its evidence companion exists and nothing needs authoring

To clear this: Nothing to do — the companion already exists.

Reported by node_occ_companion_effect (decline code already_bound, OMN-16665). This decision was made against the PR's LIVE state at compute time, not at publish time — a green publisher job only means the command reached the broker.

@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind did not rebind this PR.

This PR's evidence-source stamp line names OCC#10457, which is merged. A second companion, OCC#10481, was minted for this PR, but a merged companion is settled evidence — the merged-companion gate may already have passed against it — so the stamp was left pointing at OCC#10457 and nothing was written.

To clear this: OCC#10481 is redundant and can be closed. If the binding really should move, change the stamp by hand.

Reported by occ_companion_emitter (OMN-18089).

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 0

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 5 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] uv.lock, omnibase-core package entry (glm-review) — New package hashes accepted without provenance verification | The diff swaps sdist and wheel hashes for omnibase-core 0.47.18 as generated by uv lock. No evidence in the diff or commit message indicat
  • [MAJOR] uv.lock, omnibase-core dependencies block (glm-review) — Dependency list of omnibase-core unchanged across the version bump | The version bump changes only the version string and artifact URLs; the dependencies block (blake3, tree-sitter, etc.) is byte-id
  • [MAJOR] docker/runners/runner-image.lock.json (glm-review) — No visible test or integration coverage for the bump | The diff touches only lock and config files. There are no accompanying test changes, canary runner validation, or CI job changes that exercise th
  • [MINOR] pyproject.toml, dependencies and override-dependencies blocks (glm-review) — omnibase-spi and omnibase-compat pins not evaluated for compatibility | The comment in pyproject.toml references specific upstream core PRs (#1439, #1440) carried by the new release, but omnibase-spi
  • [MINOR] pyproject.toml, dependencies section comment (glm-review) — Stale comment about git-rev override | The comment block referencing OMN-17802 explains why a git-rev override is not active, tied to the 0.47.17 rationale. After bumping to 0.47.18 the comment no lon

@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Critical findings: 0
Major findings: 1
Total findings: 5
Models succeeded: glm-review

Note: Fewer than 2 reviewer models succeeded. Degraded results are informational (OMN-8468/OMN-8524) and do not block merge. Error: cli_review exit 2 (fewer than 2 models succeeded — partial/total outage)


Semantics (OMN-17492 — the model finds, thread resolution gates)

Surface Meaning Blocks merge?
Review threads Per-finding, posted by the reviewer No (informational)
Hostile Review Thread Gate Deterministic: unresolved hostile-reviewer threads exist Fails until resolved (not yet a required context)
degraded verdict Fewer than 2 models succeeded (infra) No

Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review, qwen3-review-b, glm-review (OMN-8468/OMN-8524/OMN-17492)

jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Sep 19, 2026
…ibase_infra#3855 (#10481)

* evidence(OMN-18595): author OCC companion for OmniNode-ai/omnibase_infra#3855

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 2a723ca25addf4268b64233ed52957a26b25078f.

* evidence(OMN-18595): self-bind OCC#10481 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
…47.18

Both are derived from the core pin and both were stale against the bump, so
CI failed on them rather than on anything the bump broke.

The fallback version matrix is regenerated by the command its own test names,
scripts/update_version_matrix.py, which moves the core range to
>=0.47.18,<0.48.0.

The released-core seam fixture freezes the published surface infra consumes
and is hand-maintained by its own update procedure, which every previous
cascade bump followed; the bot-opened PR omitted it. Only the frozen version
moves. The symbol and typed-field surface is unchanged and still verifies
against the installed 0.47.18, which is what the seam test asserts.

Focused run: tests/unit/runtime/test_seam_released_core_pin.py and
tests/unit/runtime/test_fallback_matrix_sync.py, 4 passed.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 4
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 4 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] tests/fixtures/seams/core_release/0.46.11_expected_symbols.json (glm-review) — Seam fixture surface unchanged across core version bump | The fixture's own update procedure requires re-running the seam test and recording the new surface only after confirming every consumer type-c
  • [MINOR] tests/fixtures/seams/core_release/0.46.11_expected_symbols.json (glm-review) — Fixture filename diverges from pinned core version | The file is named 0.46.11_expected_symbols.json but now pins core_version 0.47.18. The filename was already stale at 0.47.17, and this diff touches
  • [MINOR] docker/runners/runner-image.lock.json (glm-review) — Runner image identity digests updated without provenance | identity_digest and shared_env_digest change alongside the core bump, but image_version remains 8. If image_version gates image rebuild or ca
  • [MINOR] pyproject.toml (glm-review) — No release-notes or changelog evidence for the core bump | The comment references specific upstream features tied to prior bumps (core #1439, #1440) but the 0.47.18 bump carries no analogous justifica

…8.34

The fallback matrix now requires core >=0.47.18, so the integration proof's
two hardcoded versions move with it: the rejected pin becomes 0.47.17 and the
accepted one 0.47.18. Without this the proof asserts the previous matrix and
fails against the one this PR ships.

The project version moves to 0.38.34 because this PR changes packaged source
and the release-identity gate refuses new packaged bytes on an already
published version; 0.38.33 published at 21:20:42Z carrying the old core pin.
That release is also what omnimarket 0.4.134 needs in order to resolve at
all, since no published omnibase_infra currently admits core 0.47.18.

Focused run: the two integration proofs plus the two unit fixtures, 8 passed.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 5 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] tests/fixtures/seams/core_release/0.46.11_expected_symbols.json (glm-review) — Seam fixture version bumped but symbol surface unchanged | The fixture exists to freeze the exact symbol surface consumed from omnibase-core and fail loudly when it drifts. The diff bumps core_version
  • [MAJOR] docker/runners/runner-image.lock.json (glm-review) — Runner image lock digests regenerated without corresponding install-args or source changes | identity_digest and shared_env_digest both changed, but the only dependency change in the diff is omnibase-
  • [MINOR] tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py (glm-review) — Version matrix tests updated mechanically with no negative boundary case | The rejection test now asserts 0.47.17 is rejected and the acceptance test asserts 0.47.18 is accepted. There is no test for
  • [MINOR] src/omnibase_infra/runtime/version_compatibility.py (glm-review) — Fallback matrix max_version not revisited after pin bump | min_version moved to 0.47.18 while max_version remains 0.48.0. If 0.47.x releases continue, this is fine, but the constraint allows any 0.47.
  • [MINOR] tests/fixtures/seams/core_release/ (glm-review) — Stale fixture filename no longer matches recorded core version | The file is named 0.46.11_expected_symbols.json but now records core_version 0.47.18. This predates the diff in origin but the diff act

….34 relock

The version bump relocked uv.lock, which is an input to the runner image's
shared-env digest, so the value regenerated two commits ago went stale again.
This is the last lockfile-touching change on the branch, so this digest is
the one that ships. Only the two derived digests move.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 0

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 5 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] tests/fixtures/seams/core_release/0.46.11_expected_symbols.json (glm-review) — Seam fixture version bumped without any symbol surface change | The fixture's stated purpose is to fail loudly when the core pin moves, freezing the exact symbols and field types consumed. The diff ch
  • [MAJOR] docker/runners/runner-image.lock.json (glm-review) — Unexplained digest churn in runner-image.lock.json | identity_digest and shared_env_digest both change, yet the only dependency change in the diff is omnibase-core. shared_env_install_args, uv_version
  • [MINOR] tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py (glm-review) — No test coverage for the upper bound of the fallback matrix | The matrix retains max_version 0.48.0 through three consecutive pin bumps. Tests cover rejection of the immediately previous version and a
  • [MINOR] uv.lock (glm-review) — uv.lock upload timestamps dated in the future | The PyPI upload-time values for omnibase_core 0.47.17 and 0.47.18 are 2026-09-18 and 2026-09-19. These timestamps come from the registry index and canno
  • [MINOR] src/omnibase_infra/runtime/version_compatibility.py (glm-review) — Triple-maintained version pin invites drift | The omnibase-core version now lives in pyproject dependencies, [tool.uv] override-dependencies, the _FALLBACK_MATRIX, the seam fixture, and uv.lock. This

…se-core-0.47.18-omn-18595

# Conflicts:
#	docker/runners/runner-image.lock.json

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 4
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 4 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] tests/fixtures/seams/core_release/0.46.11_expected_symbols.json (glm-review) — Seam fixture bumped in metadata but surface unchanged | The fixture's stated purpose is to fail loudly when the omnibase-core surface changes. The diff changes _comment and core_version to 0.47.18 but
  • [MINOR] tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py (glm-review) — Rejection test only ever exercises the immediately preceding pin | test_fallback_matrix_rejects_the_previous_core_pin is updated from 0.47.16 to 0.47.17, keeping the test perpetually one patch behind
  • [MINOR] src/omnibase_infra/runtime/version_compatibility.py (glm-review) — Core pin duplicated across four sites with no drift guard visible | The 0.47.18 bump must be replicated in pyproject.toml dependencies, pyproject.toml override-dependencies, uv.lock (three locations),
  • [MINOR] docker/runners/runner-image.lock.json (glm-review) — Runner image identity digests changed with no provenance in diff | identity_digest and shared_env_digest in runner-image.lock.json are both rotated. The only plausible driver in this diff is the omnib

@jonahgabriel
jonahgabriel merged commit a5f22a3 into dev Sep 19, 2026
151 of 153 checks passed
@jonahgabriel
jonahgabriel deleted the automation/bump-omnibase-core-0.47.18-omn-18595 branch September 19, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant