chore(deps): bump build from 1.5.1 to 1.6.0 - #1774
Conversation
Bumps [build](https://github.com/pypa/build) from 1.5.1 to 1.6.0. - [Release notes](https://github.com/pypa/build/releases) - [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst) - [Commits](pypa/build@1.5.1...1.6.0) --- updated-dependencies: - dependency-name: build dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
1d591e56b2fc4ec15c2f958bfc659f6150308c16. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- CodeQL PR/CodeQL compatibility analysis (actions): FAILURE (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079632280/job/101692415265)
- CodeQL PR/CodeQL compatibility analysis (python): FAILURE (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079632280/job/101692415132)
- CodeQL compatibility analysis (actions) check run: failure (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079632280/job/101692415265)
- CodeQL compatibility analysis (python) check run: failure (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079632280/job/101692415132)
- Required Noema Review/noema-review: FAILURE (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079631544/job/101625294282)
- noema-review check run: failure (https://github.com/ContextualWisdomLab/fast-mlsirm/actions/runs/34079631544/job/101625294282)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: package.txt"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: package.txt"]
R1 --> V1["required checks"]
OpenCode Review Overview
|
|
Current RCA: the Required Noema Review failure on exact head This exact consumer evidence is now attached to canonical owner |
seonghobae
left a comment
There was a problem hiding this comment.
Fresh exact-head dependency review finds the effective delta correctly scoped to requirements/package.txt: build 1.5.1 → 1.6.0 with no change to the unpinned requirements/package.in authority. The two committed 1.6.0 hashes match the upstream PyPI sdist/wheel artifacts published via Trusted Publishing, and exact-head CI, repository CodeQL, Semgrep, and Security Scan are terminal GREEN. I found no package-source or hash-integrity repair to make. This is not merge authorization: Required CodeQL PR 34079632280 is terminal failure in the central required-workflow lane and there is no basis to weaken/copy that control into this dependency leaf. Preserve the one-file delta and reacquire the canonical required-workflow/independent-review gates before normal landing; do not use a no-op rebase/retrigger or predecessor evidence as a substitute.
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review of 1d591e56b2fc4ec15c2f958bfc659f6150308c16: the effective delta is limited to requirements/package.txt, updating build==1.5.1 to 1.6.0 and replacing the two hashes. This is relevant to the package/release supply-chain boundary because upstream 1.6.0 includes the fix for --dependency-constraints-txt handling that could silently separate/drop a hashed requirement continuation. The branch has exact-head CI success and repository CodeQL/Security/Semgrep success. I found no leaf-source defect in this one-file lock update.
This is a COMMENT review, not self-approval. Normal landing still requires a qualifying independent approval and the repository-required central CodeQL lane; current CodeQL PR generation for this SHA is a central-owner failure. Do not add a no-op source commit or weaken dependency/hash verification to obtain a rerun.
|
Current authority refresh for exact dependency head
Keeping this unchanged Dependabot leaf Ready would only replay known central admission failures. Re-enter Ready when the central prerequisite materially changes, then reacquire one unchanged-head terminal gate set and an independent approval. No dependency/hash weakening, no-op commit, broad/manual retrigger, self-approval, bypass, or predecessor-evidence substitution. |
|
Infrastructure-exception merge assessment for exact head The one-file change upgrades yanked The remaining failures were inspected: CodeQL jobs 102036428174 and 102036427187 report rerun without an authenticated terminal verdict; Noema job 101625294282 failed with gateway HTTP 502 after one attempt/917.9 seconds; OpenCode job 101641315597 reports a missing current-head review receipt. These are missing infrastructure/provider verdicts, not passing reviews, and remain unverified. Canonical remediation is tracked by ContextualWisdomLab/.github#1929 and #1948; no review, status, workflow or scan result will be fabricated. The user's explicit infrastructure exception permits a minimal administrative merge despite these controls. Source/hash validation and successful substantive security checks are preserved. No repository rules or workflows will be changed. Post-merge package/CI execution will be inspected; any regression requires repair or revert, and canonical review/CodeQL evidence remains outstanding until actually delivered. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bumps build from 1.5.1 to 1.6.0.
Release notes
Sourced from build's releases.
Changelog
Sourced from build's changelog.
... (truncated)
Commits
7ac9efechore: prepare for 1.6.0e57e2bf👷 ci: use app token for releases (#1169)66438abpre-commit: bump repositories (#1167)4ed9658build(deps): bump the github-actions group with 3 updates (#1166)c76707f🔧 chore: batch dependency updates weekly on Tuesday (#1165)b317437Drop a few PyPy-specific test skips (#1164)561f331pre-commit: bump repositories (#1163)9456281refactor: drop redundantexc_infoparameter from backend exception wrapper ...3e7a445Use stdlibimportlib.metadatafor typing (#1162)9a2e1e9tests: download integration sources once per run (#1157)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)