Skip to content

Pin dependencies - #13

Open
Coldaine wants to merge 2 commits into
mainfrom
renovate/ci-and-development-environment
Open

Coldaine wants to merge 2 commits into
mainfrom
renovate/ci-and-development-environment

Conversation

@Coldaine

@Coldaine Coldaine commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

User description

Review required: check dependency impact and CI before merging. Routine domain groups and separate major upgrades share two PR slots per repository; queued updates wait for a slot and the next Monday run.

This PR contains the following updates:

Package Type Update Change
actions/checkout action pinDigest → 11d5960
actions/setup-python action pinDigest → a26af69
actions/upload-artifact action pinDigest → ea165f8
codecov/codecov-action action pinDigest → ab904c4
python uses-with minor 3.11 → 3.14

Release Notes

actions/python-versions (python)

v3.14.7: 3.14.7

Compare Source

Python 3.14.7

v3.14.6: 3.14.6

Compare Source

Python 3.14.6

v3.14.5: 3.14.5

Compare Source

Python 3.14.5

v3.14.4: 3.14.4

Compare Source

Python 3.14.4

v3.14.3: 3.14.3

Compare Source

Python 3.14.3

v3.14.2: 3.14.2

Compare Source

Python 3.14.2

v3.14.1: 3.14.1

Compare Source

Python 3.14.1

v3.14.0: 3.14.0

Compare Source

Python 3.14.0

v3.13.15: 3.13.15

Compare Source

Python 3.13.15

v3.13.14: 3.13.14

Compare Source

Python 3.13.14

v3.13.13: 3.13.13

Compare Source

Python 3.13.13

v3.13.12: 3.13.12

Compare Source

Python 3.13.12

v3.13.11: 3.13.11

Compare Source

Python 3.13.11

v3.13.10: 3.13.10

Compare Source

Python 3.13.10

v3.13.9: 3.13.9

Compare Source

Python 3.13.9

v3.13.8: 3.13.8

Compare Source

Python 3.13.8

v3.13.7: 3.13.7

Compare Source

Python 3.13.7

v3.13.6: 3.13.6

Compare Source

Python 3.13.6

v3.13.5: 3.13.5

Compare Source

Python 3.13.5

v3.13.4: 3.13.4

Compare Source

Python 3.13.4

v3.13.3: 3.13.3

Compare Source

Python 3.13.3

v3.13.2: 3.13.2

Compare Source

Python 3.13.2

v3.13.1: 3.13.1

Compare Source

Python 3.13.1

v3.13.0: 3.13.0

Compare Source

Python 3.13.0

v3.12.14: 3.12.14

Compare Source

Python 3.12.14

v3.12.13: 3.12.13

Compare Source

Python 3.12.13

v3.12.12: 3.12.12

Compare Source

Python 3.12.12

v3.12.11: 3.12.11

Compare Source

Python 3.12.11

v3.12.10: 3.12.10

Compare Source

Python 3.12.10

v3.12.9: 3.12.9

Compare Source

Python 3.12.9

v3.12.8: 3.12.8

Compare Source

Python 3.12.8

v3.12.7: 3.12.7

Compare Source

Python 3.12.7

v3.12.6: 3.12.6

Compare Source

Python 3.12.6

v3.12.5: 3.12.5

Compare Source

Python 3.12.5

v3.12.4: 3.12.4

Compare Source

Python 3.12.4

v3.12.3: 3.12.3

Compare Source

Python 3.12.3

v3.12.2: 3.12.2

Compare Source

Python 3.12.2

v3.12.1: 3.12.1

Compare Source

Python 3.12.1

v3.12.0: 3.12.0

Compare Source

Python 3.12.0


Configuration

📅 Schedule: (in timezone America/Chicago)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


CodeAnt-AI Description

Secure and stabilize CI workflows

What Changed

  • CI and visual-test workflows now use fixed versions of checkout, Python setup, artifact upload, and coverage reporting actions
  • Checkout jobs no longer retain repository credentials on the runner
  • Linting continues to run on Python 3.11 while test jobs use their configured Python versions

Impact

✅ Reproducible CI runs
✅ Lower risk from changing third-party actions
✅ Reduced exposure of repository credentials

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Note

Pin GitHub Actions to fixed commits and disable credential persistence in CI workflows

  • Replaces mutable version tags with fixed commit references for checkout, setup-python, codecov-action, and upload-artifact across ci.yml and visual-tests.yml
  • Sets persist-credentials: false on all checkout steps so Git credentials are not saved in the local Git config
  • Risk: pinned commits must be manually updated when new action releases are needed

Macroscope summarized 5c4c363.

@Coldaine Coldaine added agent-review Needs agent review before merge dependencies Dependency update or dependency-management config labels Sep 22, 2026
@Coldaine Coldaine self-assigned this Sep 22, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@codeant-ai

codeant-ai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 5c4c363 Sep 23, 2026 · 20:20 20:20
✅ Reviewed your PR 1f542a9 Sep 22, 2026 · 17:01 17:03

@codeant-ai

codeant-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added the size:S This PR changes 10-29 lines, ignoring generated files label Sep 22, 2026
@codeant-ai

codeant-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. The step is named for Python 3.11 but installs Python 3.14, so workflow logs and CI reports identify the tested interpreter incorrectly.

Inconsistent naming · .github/workflows/visual-tests.yml:236

…dentials.

The pin change had moved two setup-python steps to 3.14 while the test matrix and mypy target stay on 3.11. Those jobs do not push.

Co-authored-by: Cursor <cursoragent@cursor.com>

@Coldaine Coldaine left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the CI action pins on 5c4c363.

The SHAs match the tags they name. actions/checkout v4 is 11d5960a326750d5838078e36cf38b85af677262. actions/setup-python v5 is a26af69be951a213d495a4c3e4e4022e16d87065. codecov/codecov-action v3 is ab904c41d6ece82784817410c45d8b8c02684457. actions/upload-artifact v4 is ea165f8d65b6e75b540449e92b4886f43607fa02.

The pin edit had changed the lint job and one visual-test job from Python 3.11 to 3.14. requires-python is >=3.11, the classifiers name 3.11 and 3.12, mypy is set to 3.11, and the test matrix stays 3.11 and 3.12. Those two steps are 3.11 again. The test matrix was left as it was.

The four checkout steps now set persist-credentials to false. The jobs do not push. The workflows were not executed.

No prior inline comments were open. This branch still uses checkout v4. The v7 pin is the other open pull request.

Comment thread .github/workflows/ci.yml

- name: Upload coverage to Codecov
uses: codecov/codecov-action@v3
uses: codecov/codecov-action@ab904c41d6ece82784817410c45d8b8c02684457 # v3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SUGGESTION: codecov/codecov-action is pinned to the deprecated v3 line, and this diff is the last cheap chance to move off it.

Every other action in this PR keeps its prior major (checkout v4, setup-python v5, upload-artifact v4); only codecov stops at v3. codecov/codecov-action@v3 depends on the legacy Codecov uploader, which Codecov deprecated and which is scheduled for full shutdown — after that the upload step at .github/workflows/ci.yml:74-80 silently stops reporting (fail_ci_if_error: false hides the failure), and the coverage gate must then be read only from the pytest step's --cov-fail-under=75.

Moving the pre-existing v3 pin to a v4/v5 commit digest is a larger change than this Renovate PR's scope, so this is a follow-up rather than a blocker. When you take it, add codecov/codecov-action to renovate.json's grouping (or a dedicated PR) and re-verify the updated file: input, which changed shape between v3 and v4+ (file: is deprecated in favor of files:).


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@kilo-code-bot

kilo-code-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: 1 Issue Found | Recommendation: Address before merge

Model: kilo/deepseek/deepseek-v4.1-flash — thinking level: default/reasoning (medium). Stated per review instructions.

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1

Verdict: The dependency-bump mechanics of this PR are clean and I recommend merging after the one follow-up note (or accepting it as a tracked follow-up). No correctness, security, or logic defects were found in the changed lines.

Issue Details (click to expand)

SUGGESTION

File Line Issue
.github/workflows/ci.yml 75 codecov/codecov-action stays pinned to the deprecated v3 tag/uploader while every sibling action keeps its prior major. Legacy uploader is scheduled for shutdown; with fail_ci_if_error: false the coverage upload will fail silently afterwards. Follow-up, not a blocker for this pin PR.

Analysis Notes

SHA pin verification (independent): The four digests match the majors named in their trailing comments — actions/checkout v4 = 11d5960, actions/setup-python v5 = a26af69, actions/upload-artifact v4 = ea165f8, codecov/codecov-action v3 = ab904c4. Pins are correct.

The one thing I actively re-checked because the PR touched it: Renovate's first commit bumped two lint jobs to Python 3.14. Commit 5c4c363 reverted both python-version inputs to '3.11' (.github/workflows/ci.yml:93, .github/workflows/visual-tests.yml:240), so after this PR no workflow uses 3.14. That aligns the toolchain with pyproject.toml (requires-python >=3.11, ruff target-version = py311, mypy python_version = "3.11", test matrix ['3.11','3.12']) and with README.md:7,33. No stale 3.14 documentation was introduced anywhere in the repo. Consistent — no action needed.

The step name at .github/workflows/visual-tests.yml:237 ("Set up Python 3.11") now also matches its python-version: '3.11' input again; the mismatch CodeAnt flagged on the earlier commit is resolved and was not re-reported.

Documentation Audit (per review instructions)

I searched the whole repo and read the key docs before the diff. Findings, kept as context rather than blockers since none are changable lines in this PR:

  • No AGENTS.md and no root routing doc exist. There is no single entry point that routes an agent to the plan/status/architecture docs, and no ARCHITECTURE.md. README.md partially serves this role.
  • No north-star doc exists by that name. shortcut-sage-bible.md is the de-facto north star (vision, principles, MVP scope, architecture, contracts) and is worth reading first; README-ShortcutSage-Notion.md reveals it was generated as a Notion import pack rather than living project doctrine.
  • Docs are fragmented across four roots: docs/plans/, docs/updates/, docs/researchReq/, docs/, plus four Markdown files at repo root. Several are verbatim agent prompts (docs/shortcut_sage_autonomous_agent_prompt_*.md, docs/..._handbook_save_only.md, agent-prompt-pr-train.md) that describe a feat/phase-XX-<slug> monorepo PR train which does not match the current flat repo or renovate/ branch reality.
  • Executed plans and past-dated artifacts are still present, which the review instructions say should be removed once executed:
    • docs/plans/StagedImplementation.md (generated 2025-10-14, status "Ready for execution", says "← [Current: Implementing]" at PR-02) — PR-02 through PR-05 are all complete and merged; stale.
    • docs/plans/PR-05-overlay-checklist.md — its own DoD is checked off and it records "✅ Completed as PR Add automated visual testing with Claude vision validation #8"; executed plan retained.
    • docs/plans/Possible plan.txt — a 0-byte tracked placeholder file.
    • docs/updates/2025-11-08-project-status.md and docs/updates/2025-11-11-status-progress.md — dated snapshots annotated "Next Update: After PR-05 or PR-06 completion"; that point has passed.
    • docs/researchReq/dbus-buffer-debug.md — an open research request tied to the PR-05 integration suite; check whether the GetBufferState issue was since fixed and the file can be retired.
  • Concrete staleness example: implementation-plan.md (PR-gated plan) and docs/plans/StagedImplementation.md both name the default branch master, while the live default branch is main (this PR's base is main) and ci.yml:4-7 triggers on both main and master and feat/**. docs/shortcut_sage_pr_train_operator_handbook_save_only.md:20 explicitly hedges "master (or main)".
  • Reference gap: README.md:217 links CONTRIBUTING.md, which is not tracked in the repository (would render as a dead link).

None of the above is on a line changed by this PR, so per the review rules it is reported here in the summary only and not as an inline comment.

Files Reviewed (2 files)

  • .github/workflows/ci.yml — 1 suggestion (deprecated codecov v3 pin)
  • .github/workflows/visual-tests.yml — no issues (SHA pin, persist-credentials: false, and reverts to 3.11 all verified)

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

@Coldaine

Copy link
Copy Markdown
Collaborator Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent-review Needs agent review before merge dependencies Dependency update or dependency-management config size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants