Skip to content

chore(deps): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 - #914

Closed
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/pip/main/types-requests-2.33.0.20260712
Closed

chore(deps): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712#914
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/pip/main/types-requests-2.33.0.20260712

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps types-requests from 2.33.0.20260518 to 2.33.0.20260712.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [types-requests](https://github.com/python/typeshed) from 2.33.0.20260518 to 2.33.0.20260712.
- [Commits](https://github.com/python/typeshed/commits)

---
updated-dependencies:
- dependency-name: types-requests
  dependency-version: 2.33.0.20260712
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 10, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 10, 2026 13:36
@seonghobae
seonghobae marked this pull request as draft August 11, 2026 07:01

Copy link
Copy Markdown
Contributor

Exact-head fail-closed RCA for e8998388796ac575ea5b12f26b37a4a37a9f0e1b against independently resolved live main 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba:

  • This PR changes only requirements-strix-ci-hashes.txt, the hash lock consumed by Strix automation.
  • The protected-main Strix Changed Path Quality CI pull-request path list omits that lock, so no exact-head Strix quality run exists. Generic security/supply-chain successes do not substitute for the missing consuming boundary.
  • Immediate cause: incomplete trigger coverage. Technical root cause: the executable dependency contract and its quality trigger are not co-owned. Control cause: dependency leaves can appear gate-clean without exercising the consumer.
  • The PR is Draft until an authoritative path-filter repair reaches protected main and a refreshed exact head produces terminal-success Strix quality evidence.
  • Central repair is writer-conflicted this invocation: open PRs fix(coverage): retry transient trusted uv downloads #790 and fix(coverage): replace stale LLVM runtime-boundary repair #827 both modify .github/workflows/strix-changed-path-quality-ci.yml. This loop will not create a third competing writer or weaken gates.

@seonghobae
seonghobae marked this pull request as ready for review August 12, 2026 04:08

Copy link
Copy Markdown
Contributor

@opencode-agent review

Review exact current head e8998388796ac575ea5b12f26b37a4a37a9f0e1b against independently resolved live main 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. 16 exact-head hosted workflows are terminal-success and no review thread is unresolved. Verify the types-requests dependency update is limited to the declared typing package and exact lock evidence, with no production or workflow authority change. Automated judgment is not qualifying independent human approval or merge authorization.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head dependency review for e8998388796ac575ea5b12f26b37a4a37a9f0e1b.

The diff is mechanically bounded to the types-requests exact version and its two SHA-256 hashes, and the eight directly observed generic security/supply-chain workflows are successful. However, this head has no Strix Changed Path Quality CI result even though it changes requirements-strix-ci-hashes.txt, which is executable supply-chain input to the Strix workflow.

The first causal boundary is the incomplete Strix path trigger tracked and repaired by #935. Do not treat the absent gate as success. After #935 reaches protected main, rebase/recreate this Dependabot branch so the manifest change triggers Strix on the resulting exact head; then reacquire review and branch-protection evidence. I am withholding approval rather than manufacturing a source defect in this one-line dependency update.

Copy link
Copy Markdown
Contributor

Exact-head gate status for e8998388796ac575ea5b12f26b37a4a37a9f0e1b: this PR changes only requirements-strix-ci-hashes.txt. Generic security/supply-chain checks cannot prove the regenerated hash-locked Strix environment installs, imports, and executes correctly.

Do not approve or merge until #935 is protected-merged (or equivalent permanent trigger behavior exists), this head is rebased/recreated if required, and the resulting exact head passes the full Strix dependency-lock/model-pool/syntax/clean-worktree quality workflow. Any head change invalidates prior evidence.

@seonghobae
seonghobae enabled auto-merge (squash) August 13, 2026 04:32
CWE-494/CWE-829: the Strix --require-hashes lock must keep both
published SHA-256 digests and must not retain 2.33.0.20260518.
Materialize a base Python lock only when every package line is an exact
SHA-256 pin or a two-token relative -r/--requirement include of a
candidate lock path. A lone --require-hashes directive, ./dotted paths,
and -r other-hashes.txt no longer enter the trusted build context.
@seonghobae

Copy link
Copy Markdown
Contributor

@opencode-agent review

Re-evaluate exact current head 3ccb141e8ff11dd332fefba558ccd63a7910cea7. 리뷰 확인 for the bounded-include increment; do not treat Checks wait as a blocker.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 3ccb141e8ff11dd332fefba558ccd63a7910cea7.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (5 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (5 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: strix-types-requests-pin.md"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: strix-types-requests-pin.md"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: materialize_base_python_requirements.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 3ccb141e8ff11dd332fefba558ccd63a7910cea7
  • Workflow run: 31754815469
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 3ccb141e8ff11dd332fefba558ccd63a7910cea7.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (5 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (5 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: strix-types-requests-pin.md"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: strix-types-requests-pin.md"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: materialize_base_python_requirements.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 14, 2026 02:11
@seonghobae
seonghobae marked this pull request as draft August 14, 2026 08:50

Copy link
Copy Markdown
Contributor

Returned to Draft because this is no longer a clean Dependabot update.

The intended slice is the types-requests pin and hash refresh with its focused Strix compatibility contract. Head 3ccb141e8ff11dd332fefba558ccd63a7910cea7 also carries unrelated trusted-uv materializer source/tests and broad governance-document changes, obscuring the dependency delta and preventing safe Dependabot recreation.

Recreate or rebuild from protected main so the effective diff contains only requirements-strix-ci-hashes.txt, the focused types-requests pin regression, and directly attributable doctoring/changelog evidence. Preserve materializer work in its authoritative PR, then rerun exact-head Strix/security/supply-chain gates and obtain independent review.

Copy link
Copy Markdown
Contributor

Closing the current branch rather than merging a contaminated dependency update. The intended types-requests lock refresh is not rejected, but this branch also carries trusted-uv materializer source/tests and governance documentation that overlap #790's actively verified security boundary. Recreate the dependency update from protected main after #790 and #935 integrate, then require a clean lock/update-only diff plus fresh exact-head Strix/security/review evidence. No ignore rule or downgrade is introduced.

@seonghobae seonghobae closed this Aug 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/main/types-requests-2.33.0.20260712 branch August 14, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant