chore(deps): bump google-cloud-bigquery from 3.42.2 to 3.43.0 - #915
chore(deps): bump google-cloud-bigquery from 3.42.2 to 3.43.0#915dependabot[bot] wants to merge 3 commits into
Conversation
Bumps [google-cloud-bigquery](https://github.com/googleapis/python-bigquery) from 3.42.2 to 3.43.0. - [Release notes](https://github.com/googleapis/python-bigquery/releases) - [Changelog](https://github.com/googleapis/python-bigquery/blob/main/CHANGELOG.md) - [Commits](https://github.com/googleapis/python-bigquery/commits) --- updated-dependencies: - dependency-name: google-cloud-bigquery dependency-version: 3.43.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Exact-head fail-closed RCA for
|
|
@opencode-agent review Review exact current head |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head dependency review: the one-file diff only changes google-cloud-bigquery and its two hashes in requirements-strix-ci-hashes.txt, and the observed generic workflows are successful. The exact head has no Strix Changed Path Quality result because the permanent manifest trigger is missing. #935 is the bounded prerequisite. After it reaches main, recreate or rebase this branch so Strix runs on the resulting exact head; then reacquire review and protection evidence. Approval and auto-merge are withheld until that evidence exists.
|
Exact-head gate status for Do not approve or merge until #935 is protected-merged (or equivalent permanent trigger behavior exists), this branch is rebased/recreated if required, and the resulting exact head passes the full Strix dependency-lock/import/model-pool/syntax/clean-worktree quality contract. Any head change invalidates prior evidence. |
CWE-494/CWE-829: the Strix --require-hashes lock must keep both published SHA-256 digests and must not retain 3.42.2.
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
|
@opencode-agent review Re-evaluate exact current head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
abc78b1bf5cfd21ee30d176e9fe565630d2cad2d. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Bandit (Python SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94522837466)
- CodeQL PR/Detect CodeQL languages: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721456042/job/94519178949)
- Detect CodeQL languages check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721456042/job/94519178949)
- Detect Python check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94519178345)
- OSV-Scanner PR/osv-scan / osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721456504/job/94519180230)
- Python 3.10 compatibility contract check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455946/job/94519178223)
- Python 3.14 full quality gate check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455946/job/94519178232)
- Python Security/Bandit (Python SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94522837466)
- Python Security/Detect Python: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94519178345)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94522836804)
- SAST Semgrep/Semgrep (multi-language SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455934/job/94519178053)
- SBOM Generation/generate-sbom: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455953/job/94519178180)
- Scorecard PR/Scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455915/job/94519178304)
- Scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455915/job/94519178304)
- Secret Scan/gitleaks (secret scan): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455957/job/94519178054)
- Security Scan/dependency-review: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178194)
- Security Scan/osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178336)
- Security Scan/scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178337)
- Security Scan/trivy-fs: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178310)
- Semgrep (multi-language SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455934/job/94519178053)
- Trusted uv Materializer Quality CI/Python 3.10 compatibility contract: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455946/job/94519178223)
- Trusted uv Materializer Quality CI/Python 3.14 full quality gate: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455946/job/94519178232)
- coverage-source-tree check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721454953/job/94522900141)
- dependency-review check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178194)
- generate-sbom check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455953/job/94519178180)
- gitleaks (secret scan) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455957/job/94519178054)
- osv-scan / osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721456504/job/94519180230)
- osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178336)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455958/job/94522836804)
- scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178337)
- trivy-fs check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31721455920/job/94519178310)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (5 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (5 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: strix-google-cloud-bigquery-pin.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: strix-google-cloud-bigquery-pin.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script: materialize_base_python_requirements.py"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (5 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (5 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: strix-google-cloud-bigquery-pin.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: strix-google-cloud-bigquery-pin.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script: materialize_base_python_requirements.py"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script: materialize_base_python_requirements.py"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
|
|
Returned to Draft because this is no longer a clean Dependabot update. The intended slice is the Recreate or rebuild from protected |
|
Closing this current branch rather than merging an overlapping dependency update. The intended |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps google-cloud-bigquery from 3.42.2 to 3.43.0.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)