Skip to content

deps(fast-mlsirm): consume immutable v0.9.1 owner release instead of stale commit pin #967

Description

@seonghobae

Finding

Protected main@83eba56149eb802cd63642c507c324c9976ec78e consumes fast-mlsirm from exact VCS commit d025b7d237d8db7ca97a5611606c6285d5870895; the committed lock identifies it as package 0.8.0. The canonical owner has immutable GitHub Release v0.9.1 at exact target 09f762ded35786dd1078222a4577ff09d649816f (published 2026-08-26). The release has no GitHub binary assets, so the consumer candidate is the exact immutable release-target commit rather than a mutable tag or copied source.

ContextualWisdomLab/fast-mlsirm remains the owner of psychometric kernels, PyO3/Rust packaging, and release provenance. LineageWeave only consumes the released/versioned owner artifact and verifies its own adapter/read-model contract.

RED → GREEN completed

Test-first lane 34071077674 reproduced the stale-pin RED, updated only the exact owner dependency, regenerated uv.lock with uv lock, selected repository-authoritative Rust 1.97.1, completed uv sync --frozen --extra dev --extra backend, passed the focused dependency contract, and passed the complete PostgreSQL-backed Python/backend suite. Owner-boundary/clean-diff verification and temporary-workflow removal also passed.

Workflow-free staging tree: 6c9014343691841e2f16f2de283094be6e595448.

Product commit 58730389eb55e4aa8d44ae4852a248d1a2b42dfd reuses that exact validated tree directly on protected main@83eba56149eb802cd63642c507c324c9976ec78e, excluding temporary workflow history.

Product PR

#970 is the current consumer implementation. It is intentionally Draft. Fresh exact-product-head workflows have started: repository-local Tests/PROV-O/Ontology jobs are Draft-skipped by repository policy; SAST, Security, and CodeQL are queued. Devin Review and CodeRabbit commit statuses are successful, but there is no qualifying independent current-head approval yet.

Do not close this issue until #970 is normally merged and the released-owner consumer path is verified on protected main. No owner source copy, Python psychometric fallback, cross-service SQL, self-approval, synthetic status, force push, destructive rebase, or gate weakening.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions