Repository navigation
chore(deps): bump omnibase-core to 0.47.22 (OMN-18595) - #3997
Conversation
Automated dependency cascade from OmniNode-ai/omnibase_core release 0.47.22. Onex-Workflow: Release Onex-Run: https://github.com/OmniNode-ai/omnibase_core/actions/runs/35770620166
…se-core-0.47.22-omn-18595
…ore 0.47.22 lock The bump re-locked uv.lock without re-binding docker/runners/runner-image.lock.json, so runner-image-build-smoke refused the stale shared_env_digest.
Re-binds docker/runners/runner-image.lock.json over dev's #3996 lock. Onex-Lane: infra-release-cut Onex-Session: 47d209ab4acb41eda442f65283f4275d
|
No OCC evidence companion was minted for this PR. product PR is a draft; companion suppressed (F-17) Matched in the state: To clear this: Mark the PR ready for review. The ready_for_review trigger re-fires the born path and the companion mints then. Reported by |
…x, seam and pin tests - version_compatibility fallback matrix floor 0.47.20 -> 0.47.22 (update_version_matrix.py) - released core pin seam fixture: version line only, no symbol or field-type drift - backmerge identity and fallback-matrix tests assert the new pin - core 0.47.22 (OMN-18996) makes on_manifest_built callback failures propagate; the corpus capture test now asserts that contract instead of the old warning Onex-Lane: infra-release-cut Onex-Session: 47d209ab4acb41eda442f65283f4275d
|
No OCC evidence companion was minted for this PR. this PR is already bound to OCC#10957; its evidence companion exists and nothing needs authoring To clear this: Nothing to do — the companion already exists. Reported by |
…ibase_infra#3997 (#10957) * evidence(OMN-18595): author OCC companion for OmniNode-ai/omnibase_infra#3997 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 6c11e495c208c7c69cd85b859b85c791a73034ac. * evidence(OMN-18595): self-bind OCC#10957 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai>
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 6
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 6 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/integration/services/test_corpus_capture_integration.py(glm-review) — Callback contract change shipped without caller-side error handling | Core 0.47.22 changes on_manifest_built semantics from warn-and-continue to fail-fast. The diff updates the test to assert the new - [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Fixture entry skips its own mandated update procedure | The fixture header states entries are recorded 'only after confirming every consumer still type-checks' and the prior entry documents mypy --str - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — Test names reference stale version constants | test_fallback_matrix_rejects_the_previous_core_pin now rejects 0.47.20, which is the pin being replaced by this very PR, not the 'previous' pin after mer - [MINOR]
src/omnibase_infra/runtime/version_compatibility.py(glm-review) — Fallback matrix upper bound excludes 0.48.x with no migration note | The matrix bump raises min_version to 0.47.22 but leaves max_version at 0.48.0. The diff does not address what happens when 0.48.0 - [MINOR]
pyproject.toml(glm-review) — Stale comment attributes pin to superseded core changes | The pyproject comment above the pin still explains the version in terms of core #1439/#1440 (OMN-17802, 0.47.20). After this change the pin is - [MINOR]
docker/runners/runner-image.lock.json(glm-review) — runner-image.lock.json digests advanced without image_version bump | identity_digest and shared_env_digest changed but image_version remains 8. If any consumer caches runner images by image_version ra
|
| Surface | Meaning | Blocks merge? |
|---|---|---|
| Review threads | Per-finding, posted by the reviewer | No (informational) |
Hostile Review Thread Gate |
Deterministic: unresolved hostile-reviewer threads exist | Fails until resolved (not yet a required context) |
degraded verdict |
Fewer than 2 models succeeded (infra) | No |
Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review, qwen3-review-b, glm-review (OMN-8468/OMN-8524/OMN-17492)
… (OMN-18595) # Conflicts: # docker/runners/runner-image.lock.json
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 5 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/integration/services/test_corpus_capture_integration.py(glm-review) — Behavioral contract change to build() not evaluated for other callers | The diff changes the exception semantics of ManifestGenerator.build(): callbacks registered via on_manifest_built now propagate - [MINOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture update skips its own documented confirmation procedure | The fixture's stated update procedure requires confirmation 'only after mypy --strict passed over all source files.' The prior ent - [MINOR]
docker/runners/runner-image.lock.json(glm-review) — Runner image lock digests regenerated without explanation | identity_digest and shared_env_digest in runner-image.lock.json changed, but the diff contains no corresponding change to dependency inputs - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — Fallback matrix rejection test does not pin the exact lower boundary | test_fallback_matrix_rejects_the_previous_core_pin now uses installed 0.47.20 against min 0.47.22. This validates one interior re - [MINOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — No seam test coverage for the removed warn-and-continue contract | The seam fixture exists to catch drift in consumed core surface. Core #1730 removed warn-and-continue behavior, a contract change tha
…se-core-0.47.22-omn-18595 # Conflicts: # docker/runners/runner-image.lock.json
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 5
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 5 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
tests/integration/services/test_corpus_capture_integration.py(glm-review) — Behavioral contract change (exception propagation) audited only via test rewrite | The diff flips the expected semantics of generator.build() from warn-and-continue to raise-and-abort, citing core #17 - [MAJOR]
tests/fixtures/seams/core_release/0.46.11_expected_symbols.json(glm-review) — Seam fixture claims surface unchanged while cited core change is purely behavioral | The fixture's update procedure is keyed on symbol and field-type drift: "the seam test reported the version line an - [MINOR]
docker/runners/runner-image.lock.json(glm-review) — Runner image identity digests bumped without corresponding recipe changes | identity_digest and shared_env_digest changed, but the diff touches no Dockerfile, install script, or shared-env source file - [MINOR]
tests/integration/runtime/test_omn17802_core_pin_fallback_matrix.py(glm-review) — Rejected-pin test is a tautological copy of the matrix | test_fallback_matrix_rejects_the_previous_core_pin hardcodes both the rejected version and the expected error string, both of which are restate - [MINOR]
src/omnibase_infra/runtime/version_compatibility.py(glm-review) — Falling-version regression path untested | The fallback matrix min_version was raised to 0.47.22, but no test asserts that installing exactly the previous pin 0.47.20 is rejected at startup/runtime (o
Summary
Successor to omnibase_infra#3970, same branch and same commits: the automated dependency bump triggered by the
omnibase_core0.47.22 release.uv.lockviauv lock --upgrade-package omnibase_corepyproject.tomlexact pin and the[tool.uv]override to==0.47.22docker/runners/runner-image.lock.json, which the bump left stale (the bump re-lockeduv.lockwithout re-binding the runner image identity, sorunner-image-build-smokeandtests/ci/test_runner_image_identity.pyrefused it)origin/dev(through the 0.38.57 bump of fix(OMN-16852): the catalog render stops handing the runtime build an empty OMNI_HOME #3996)version_compatibilityfallback-matrix floor (regenerated byscripts/update_version_matrix.py), the released-core seam fixture (version line only; the seam test reported no symbol or field-type drift), and the backmerge-identity and fallback-matrix pin testson_manifest_builtcallback failures propagate instead of warning; no infra production path registers a callback (only a docstring example), so the corpus-capture integration test now asserts the new contractWhy a successor pull request
omnibase_infra#3970 cited the upstream release companion, onex_change_control#10790, as its evidence source. That OCC snapshot carries no receipt bound to #3970, so the Receipt Gate and occ-preflight refused it (
pr_ticket_mismatch). The autobind minted the correct companion, onex_change_control#10821 (merged 2026-09-23T10:54:17Z), but the evidence-source stamp line of an existing body cannot be repointed: the PR-body stamp guard refuses any edit that drops a stamp line (OMN-18335), and the Receipt Gate refuses a body carrying two (OMN-14410). #3970 was closed with both lines intact, so no evidence line was lost. This body carries none of its own; the autobind stamps this pull request's companion.Cascade provenance (OMN-16286)
OmniNode-ai/omnibase_core0.47.22Verification
uv run python scripts/ci/runner_image_identity.py --mode verifypasses at this head (identity v8 c52a9e51)uv run pytest tests/ci/test_runner_image_identity.py: 11 passedtests/integration/services/test_corpus_capture_integration.py(7 passed); ruff and mypy strict cleanpyproject.toml,uv.lock). Lab proof is the post-merge compose-dev lab-pass receipt for the merge sha, which this lane waits on before any further runtime merge (OMN-17427 sequencing).Evidence-Ticket: OMN-18595
Evidence-Source: OCC#10957