chore(deps): bump hf-xet from 1.5.1 to 1.6.0 - #913
Conversation
Bumps [hf-xet](https://github.com/huggingface/xet-core) from 1.5.1 to 1.6.0. - [Release notes](https://github.com/huggingface/xet-core/releases) - [Commits](huggingface/xet-core@v1.5.1...v1.6.0) --- updated-dependencies: - dependency-name: hf-xet dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Fail-closed quality gate (exact head
This PR is therefore Draft until a single authoritative workflow-path repair reaches protected |
|
@opencode-agent review Review exact current head |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head dependency review: the one-file diff only changes hf-xet and its published wheel hashes in requirements-strix-ci-hashes.txt, and the observed generic workflows are successful. The exact head has no Strix Changed Path Quality result because the permanent manifest trigger is missing. #935 is the bounded prerequisite. After it reaches main, recreate or rebase this branch so Strix validates the resulting exact head; then reacquire review and branch-protection evidence. Approval and auto-merge are withheld until that evidence exists.
|
Exact-head gate status for Do not approve or merge from the generic green set alone. The permanent trigger repair in #935 must first reach protected |
CWE-494/CWE-829: the Strix --require-hashes lock must keep every published platform-wheel digest and must not retain 1.5.1.
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
|
@opencode-agent review Re-evaluate exact current head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
d8d1b0ffff67f8b6f2c4f78b087e2233dc157ac3. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Bandit (Python SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94522831113)
- Close Empty PR/close-empty: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836365/job/94520454366)
- CodeQL PR/Detect CodeQL languages: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836872/job/94520456196)
- Detect CodeQL languages check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836872/job/94520456196)
- Detect Python check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94520456251)
- OSV-Scanner PR/osv-scan / osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721837402/job/94520458384)
- Python 3.10 compatibility contract check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836847/job/94520455773)
- Python 3.14 full quality gate check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836847/job/94520455816)
- Python Security/Bandit (Python SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94522831113)
- Python Security/Detect Python: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94520456251)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94522831056)
- SAST Semgrep/Semgrep (multi-language SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836954/job/94520456372)
- SBOM Generation/generate-sbom: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836852/job/94520456160)
- Scorecard PR/Scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836837/job/94520456122)
- Scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836837/job/94520456122)
- Secret Scan/gitleaks (secret scan): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836894/job/94520456119)
- Security Scan/dependency-review: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456185)
- Security Scan/osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456509)
- Security Scan/scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456011)
- Security Scan/trivy-fs: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520455978)
- Semgrep (multi-language SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836954/job/94520456372)
- Trusted uv Materializer Quality CI/Python 3.10 compatibility contract: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836847/job/94520455773)
- Trusted uv Materializer Quality CI/Python 3.14 full quality gate: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836847/job/94520455816)
- close-empty check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836365/job/94520454366)
- coverage-source-tree check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836352/job/94522949399)
- dependency-review check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456185)
- generate-sbom check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836852/job/94520456160)
- gitleaks (secret scan) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836894/job/94520456119)
- osv-scan / osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721837402/job/94520458384)
- osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456509)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836913/job/94522831056)
- required-workflow-bootstrap check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836352/job/94520454815)
- scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520456011)
- trivy-fs check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721836858/job/94520455978)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (5 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (5 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: strix-hf-xet-pin.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: strix-hf-xet-pin.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script: materialize_base_python_requirements.py"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (5 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (5 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: strix-hf-xet-pin.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: strix-hf-xet-pin.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script: materialize_base_python_requirements.py"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
|
|
Returned to Draft because this is no longer a clean Dependabot dependency update. The intended slice is the Recreate or rebuild from protected |
|
Closing this dependency PR instead of merging its current branch. The intended |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps hf-xet from 1.5.1 to 1.6.0.
Release notes
Sourced from hf-xet's releases.
Commits
de71453bump hf-xet Python to 1.6.0 (#924)0f689efchore: bump crate versions to 1.6.0 (#925)1284224Local simulation test for v2 shards upload API (#910)f3d85bdfix: scope pyo3 auto-initialize to dev-dependencies (#891) (#923)7a26750Allow selecting the reqwest TLS backend via hf-xet features (#917)a3f7e87Embed input in the DataHash parse Error (#914)fe93e98fix: stack overflow in xet-session from unboxed futures (#908)87ca7adStream shard finalization progress via POST /v2/shards (#884)075687dchore: bump crate versions to 1.5.4 (#907)98e9348Fix bump-crates-version workflow (#906)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)