From c9fad4dd71e52e166a1b2c43d670154a2dcaf3e8 Mon Sep 17 00:00:00 2001 From: Polichinl Date: Fri, 26 Jun 2026 23:37:35 +0200 Subject: [PATCH] =?UTF-8?q?docs(risk-register):=20register=20C-44=20?= =?UTF-8?q?=E2=80=94=20defer=20pipeline-core=203.0.0=20bump=20until=20cros?= =?UTF-8?q?s-repo=20development=20is=20stable?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Records the standing constraint that the views-pipeline-core 2.x->3.x bump must not land until 3.0.0 is on PyPI AND the platform runs smoothly on development across all repos. development is green on the reproducible 2.3.0 pin; the unreleased-3.x-via-git-branch change is preserved on backup/pipeline-core-3.0.0-git-source and becomes a trivial reproducible pin once both gates clear. Tier 3. Header 43/23/20 -> 44/24/20. Cross-refs C-40, C-07, C-09. Co-Authored-By: Claude Opus 4.8 --- reports/technical_risk_register.md | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/reports/technical_risk_register.md b/reports/technical_risk_register.md index 9228e4c..1113a1b 100644 --- a/reports/technical_risk_register.md +++ b/reports/technical_risk_register.md @@ -5,8 +5,8 @@ | Project | views-postprocessing | | Owner | Dylan Pinheiro / PRIO MD&D Team | | Last Updated | 2026-06-26 | -| Total Concerns | 43 | -| Open Concerns | 23 | +| Total Concerns | 44 | +| Open Concerns | 24 | | Resolved Concerns | 20 | --- @@ -484,6 +484,24 @@ See also C-03 (the sibling enrich→validate test-coverage gap), C-22 (no post-d --- +### C-44: views-pipeline-core 3.0.0 dependency bump is pending and must not land until the platform runs on development across all repos + +| Field | Value | +|-------|-------| +| ID | C-44 | +| Tier | 3 | +| Source | `manual` (2026-06-26) — surfaced while consolidating a stranded local commit after the input-integrity sprint merge | +| Trigger | When views-pipeline-core 3.0.0 is published to PyPI **and** the platform is confirmed running smoothly on `development` across all consumer repos — then bump `pyproject.toml` to a reproducible version pin (`views-pipeline-core = ">=3.0.0,<4.0.0"`), re-lock, and PR. Do **not** land the bump before both conditions hold, and do **not** source it from a moving git branch. | +| Location | `pyproject.toml:13` (currently `views-pipeline-core = ">=2.1.3,<3.0.0"`); `poetry.lock` (pins `views-pipeline-core 2.3.0`, a reproducible PyPI wheel); the deferred change preserved on local branch `backup/pipeline-core-3.0.0-git-source` (commit `78d238e`) | + +`development` currently pins `views-pipeline-core = ">=2.1.3,<3.0.0"` and the committed `poetry.lock` resolves it to **2.3.0** from PyPI — reproducible, and the merged input-integrity sprint (#64) was CI-proven green against it. **3.0.0 is not yet on PyPI (political hold).** A local-only commit (`78d238e`, authored 2026-06-25 in a separate session, never pushed) repoints the dependency to pipeline-core's **git `development` branch** to track the unreleased 3.x "in tandem with other consumers." + +That change was deliberately **not** landed on `development` (2026-06-26), for three reasons: (a) sourcing from a **moving git branch** makes builds **non-reproducible** (the branch advances under us); (b) it is a **major-version switch** (2.x→3.x) whose breaking changes were never exercised against the just-merged sprint code; (c) it would require a **full re-lock** resolving 3.x + its transitive tree, rippling through `poetry.lock`. The maintainer's standing constraint: **the platform must run smoothly on `development` across all repos before taking the major dependency bump.** Until then the bump is premature. + +No silent corruption and no current breakage (development is green on 2.3.0) → **Tier 3** (coordination / release-sequencing / reproducibility). The deferred work is preserved (backup branch) and becomes a trivial, reproducible one-line pin once 3.0.0 ships and the cross-repo gate clears. Cross-refs C-40 (the underlying pipeline-core inheritance coupling that makes major bumps high-blast-radius), C-07 (the transitive-via-pipeline-core dependency surface), C-09 (publish-workflow version handling). + +--- + ## Disagreements ### D-09: Multi-store support — parameterize the manager now vs after the FAO global delivery