Skip to content

chore(main): release 0.2.53 - #1785

Merged
mldangelo-oai merged 4 commits into
mainfrom
release-please--branches--main
Oct 3, 2026
Merged

mldangelo-oai merged 4 commits into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Release ModelAudit 0.2.53 and modelaudit-picklescan 0.1.11. Require modelaudit-picklescan>=0.1.11,<0.2.0 so root upgrades receive the sibling fixes described in these release notes. The existing dependency guard requires explicit >= and < bounds, checks the known fixed minimum and compatible upper boundary, and allows later minimum increases and independently newer sibling releases.

Move the shipped detailed notes into their release sections, retain one empty Unreleased section first, name the locked AnyIO 4.15.1 and GitPython 3.1.62 versions in the security notes, correct the root comparison link, and remove the root-only cache runtime claim from the sibling notes. Dependency guides match the new minimum. Both release dates are October 3, 2026.

Use the canonical Release Please body delimiters, named sibling component and compatible scoped title. Offline checks against pinned Release Please 17.3.0 construct both expected releases; the old body and incompatible-title controls construct neither.

Validation of the refreshed candidate based on main 2e785193c2fbbaf6ef6c9442a19c7576b36dde9b:

  • Ruff format/check, Mypy 2.4 across all 480 files, scoped Prettier, and the actual dependency guard pass. Independent red/green checks reject the two reported exclusion-hole ranges, old and prerelease floors, inclusive upper bounds and incompatible lock versions; current, higher-floor and independently newer locked-sibling controls pass. The complete standalone Python 3.12 lane passes: 3,215 passed and 123 skipped. Standalone Mypy checks all 26 files and isolated imports pass on Python 3.10–3.13 using each profile's exact locked, hash-verified librt artifact after normal tool resolution hit the configured-index limitation below.
  • Full fast pytest stopped with 2 failed, 17,967 passed and 380 skipped in 849.11 seconds on the latest guard revision. Both failing Hugging Face streaming CLI nodes reproduce on exact current main with the same default-cache staging-identity error. Both pass their original assertions on candidate and main when an external diagnostic adds only the supported private --cache-dir option; Python and frozen dependencies match apart from the two release versions. The full local run remains incomplete; the exact-head remote test lanes passed under the workflow’s configured test selection.
  • Both packages' wheel and source distributions pass Twine. After the test-only follow-up, the root distributions were rebuilt and rechecked: the wheel is byte-identical, and the sdist differs only in the exact repaired test. Prior consumer and standalone proofs carry against unchanged installed runtime and dependency metadata. All four isolated Linux Python 3.12 wheel/source installs pass; standalone API reports are complete and clean with no root package installed, and root CLI scans of the benign fixture succeed without issues. Artifact hashes and installed import paths are recorded.
  • The built root wheel rejects sibling 0.1.10 and 0.1.11rc1, accepts 0.1.11 and 0.1.12, and rejects 0.2.0. Root, sibling, Rust and release-manifest versions agree; the fresh bot lock bytes are preserved.
  • Rust formatting, check, Clippy, and all 187 tests pass on Rust 1.97.1. Rust 1.83.0 is not installed locally; its exact-head remote MSRV checks passed in all four standalone lanes. Local native artifact validation covers Linux x86_64; the five-platform publication matrix runs after release creation.
  • The standalone lock check passes. The normal root lock check and standalone tool resolution are blocked by the configured index's missing librt 0.16 metadata; the frozen all-ci install succeeds from the existing locked artifacts. No index override, registry rewrite or dependency downgrade is included. Exact-head remote lock consistency and type checks passed.

The latest scheduled Nightly correctness run failed in existing Click/Windows cases tracked by the unfinished #1864; that repair remains unmerged.

Current head 2818eee523917f4f4c3d3fe791defd92d4bec625 completed benchmark run 37085542417: all 13 shared benchmarks are classified stable, with zero reported regressions and an aggregate median increase of 1.8% (4.310 s to 4.388 s).

Independent generic review and two fresh GPT-6 Astra Ultra native passes, checked by a distinct fresh verifier, found no actionable issues at 2818eee523917f4f4c3d3fe791defd92d4bec625. GitHub CI is terminal at this exact head: 42 checks succeeded, two expected conditional checks were skipped, and none failed or remain pending. Automated repository code and security reviews report no findings.


0.2.53

0.2.53 (2026-10-03)

Security

  • Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes.
  • Upgrade locked AnyIO to 4.15.1 and GitPython to 3.1.62 to address dependency audit advisories.
  • Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants.
  • Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature.
  • Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615.
  • Preserve model-card network alerts when documented image examples contain code outside the reviewed generated forms.

Bug Fixes

  • avoid C&C signal for check_input_dim identifiers (#1847) (f906f9a)
  • cache: ignore macOS file access-time events (#1821) (b5341b5)
  • cache: isolate Windows probes and stabilize nightly checks (#1782) (47f94ee)
  • cache: keep Windows probes out of concurrently scanned trees (#1795) (c29586b)
  • cache: preserve locked probes under directory aliases (#1787) (caa2afe)
  • cache: preserve macOS entries during ancestor churn (#1800) (2c3512b)
  • cache: preserve Windows source fingerprint cache hits (#1793) (f27ebac)
  • cache: update scan-result entries atomically on hits (#1809) (a9720c0)
  • ci: accept rotated pinned checkout digests (#1799) (704e070)
  • ci: increase nightly correctness shard capacity (#1866) (7bb0378)
  • ci: route hash timing test to performance lane (#1824) (b4c10f2)
  • compact ONNX runtime lineage fanout (#1845) (4b7ebbc)
  • deps: bump anyio from 4.13.0 to 4.14.2 (#1855) (e635b8a)
  • deps: bump gitpython from 3.1.51 to 3.1.54 (#1786) (32de965)
  • deps: bump oauthlib from 3.3.1 to 4.0.0 (#1860) (72d3777)
  • deps: harden audit coverage and vulnerable packages (#1808) (995767e)
  • deps: prevent incompatible XGBoost Renovate upgrades (#1810) (ee2025e)
  • deps: update dependency xgboost to >=3.4,<3.5 (#1805) (e84cf95)
  • docker: upgrade vulnerable runtime Debian packages (#1849) (fafb9fb)
  • docker: upgrade vulnerable util-linux runtime packages (#1813) (521e941)
  • downgrade passive model metadata URLs (#1837) (de299cf)
  • ggml: detect embedded ZIP polyglot payloads (#1780) (9631527)
  • ignore ONNX tensor bytes for network text (#1840) (12c6287)
  • install tomli for Python 3.10 runtime (#1843) (242e08b)
  • joblib: fail closed on inconclusive warning scans (#1796) (a54bddc)
  • mlflow: restore SQL-backed registry support (#1818) (3e4e3c9)
  • network: block README remote-code trust bypasses (#1788) (65111fe)
  • network: preserve detections in README environment files (#1790) (5c1b267)
  • network: reject side-effectful model-card image examples (#1825) (56417b8)
  • picklescan: avoid scalar storage pickle false positives (#1842) (7408ed1)
  • picklescan: diagnose Windows call-graph source-stability failures (#1789) (89b5024)
  • picklescan: preserve nested storage probe coverage (#1846) (28ad1c9)
  • picklescan: safely parse bounded PyTorch tensor batches (#1783) (705059c)
  • preserve caller-owned Hugging Face cache sidecars (#1792) (eeb0be6)
  • preserve ONNX shape provenance during weight analysis (#1838) (54d14c3)
  • preserve PyTorch storage import trust (#1841) (a2f040e)
  • recognize bounded official image downloads in model cards (#1784) (64d4f52)
  • remove tensor_name_count retention budget dimension for remote SafeTensors (#1822) (4c24e17)
  • safely suppress verified Hugging Face model-card image examples (#1791) (6ee2b36)
  • scan encoded pickle metadata within byte budget (#1839) (169cd17)
  • tests: preserve fail-closed multi-array Joblib scans (#1819) (217f127)
  • treat CoreML license references as informational (#1852) (604bed5)
  • trust complete legacy PyTorch storage layout (#1850) (08d9fee)
  • validate manual release versions before outputs (#1794) (13431f6)
  • Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs.
  • Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage.
  • Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations.
  • Preserve incomplete-scan diagnostics for malformed or unsupported ZIP data in GGUF/GGML files, including cached scans.
  • Report incomplete coverage when a GGUF/GGML source changes during scanning.
  • Preserve caller-owned Hugging Face cache sidecars during streaming cleanup.
  • Keep incomplete Joblib NumPy-wrapper scans failed closed when embedded pickle analysis also reports warnings.
  • Upgrade XGBoost to 3.4 on Python 3.12+ while retaining XGBoost 3.2 on Python 3.10 and 3.11.
  • Restore SQL-backed MLflow model registries and upgrade their vulnerable SQL parser.
  • Remove tensor_name_count as a retention budget dimension for remote SafeTensors streaming; the result_bytes cap already bounds aggregate serialized size, so large multi-shard models (e.g. 141 shards) no longer fail closed prematurely.
  • Avoid false-positive urllib network findings for model cards whose only urlopen use is the documented Image.open(urlopen(...)) sample-image example.
  • Upgrade vulnerable locked dependencies, use the hardened MLflow tracking client, and audit all installed CI extras.
  • Avoid network false positives for bounded README examples that download sample images over HTTPS from Hugging Face.
  • Preserve network security findings in README-named environment files.
  • Preserve README network detections when Transformers examples enable or dynamically configure remote code execution, including through generate(custom_generate=...).
  • Avoid ONNX network false positives from tensor payload bytes while preserving metadata URL/IP ownership and fail-closed coverage for truncated structured extraction or unknown protobuf fields.
  • Preserve Windows source-fingerprint cache hits while continuing to reject swapped or modified files.
  • Prevent Windows cache identity probes from creating locked temporary files inside scanned directories.
  • Preserve locked Windows cache probes reached through directory aliases while clearing stale scan results.
  • Place cross-volume Windows cache identity probes near the volume root instead of the nearest ancestor of the scanned path, so a probe can no longer appear inside a directory tree that a concurrent scan is walking.
  • Keep published scan-result cache entries readable when concurrent or interrupted hits update access metadata.
  • Preserve macOS scan-result cache entries during unrelated temporary-file churn while rejecting replaced source files and directories.
  • Keep macOS scan-result caching enabled when hashing updates a model file's access time.
  • Keep scanning referenced PyTorch storage members when hidden pickle, encoded literal, frame-first, or malformed-separator payloads cross trusted probe boundaries.
  • Preserve call-graph coverage for source-backed builtin aliases and non-canonical stdlib mailbox constructors.
  • Scan all bounded encoded pickle metadata that fits the decoded-byte budget, avoiding incomplete PyTorch ZIP coverage on harmless small encoded tokens.
  • Install tomli for Python 3.10 runtime environments so no-default-groups scanner installs can read ModelAudit TOML configuration.
  • Avoid command-and-control false positives for generated TorchScript _check_input_dim identifiers while preserving actionable check_in detections.
  • Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain.
  • Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections.
  • Require modelaudit-picklescan>=0.1.11 so root upgrades receive the released scanner fixes.
modelaudit-picklescan: 0.1.11

0.1.11 (2026-10-03)

Bug Fixes

  • picklescan: avoid scalar storage pickle false positives (#1842) (7408ed1)
  • picklescan: diagnose Windows call-graph source-stability failures (#1789) (89b5024)
  • picklescan: preserve nested storage probe coverage (#1846) (28ad1c9)
  • picklescan: safely parse bounded PyTorch tensor batches (#1783) (705059c)
  • preserve PyTorch storage import trust (#1841) (a2f040e)
  • Ignore canonical PyTorch storage persistent-ID globals during source-sensitive call-graph enrichment.
  • Report which snapshot gate invalidated a shared call-graph source-stability failure.
  • Validate bounded batched PyTorch state-dictionary entries without falsely flagging canonical tensor reconstruction.
  • Keep scanning PyTorch storage members when hidden pickle, encoded literal, frame-first, or malformed-separator payloads cross trusted probe boundaries.
  • Preserve call-graph coverage for source-backed builtin aliases and non-canonical stdlib mailbox constructors.

This release PR was generated with Release Please.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7443a9b4b3

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md Outdated
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from 3a3ce02 to b35fc94 Compare August 1, 2026 12:55

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cfcbce8b27

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/modelaudit-picklescan/CHANGELOG.md Outdated
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 4 times, most recently from 94ff649 to ddd7053 Compare August 24, 2026 05:05

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 76ac63fdb3

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/modelaudit-picklescan/CHANGELOG.md Outdated
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 6 times, most recently from a1cf042 to 18dbf42 Compare August 24, 2026 22:02

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 85c5e7e1cb

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md
Comment thread CHANGELOG.md Outdated
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 4 times, most recently from c9c434d to 172fdae Compare August 28, 2026 20:47

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ee98d35ec4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/modelaudit-picklescan/CHANGELOG.md
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 7 times, most recently from 4f3a861 to f86d693 Compare August 31, 2026 07:55
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from 13de6e9 to 7ee6e29 Compare September 29, 2026 18:20

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bff55f2f65

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from bff55f2 to 9cb009b Compare September 29, 2026 19:30

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9cb009b894

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 41d37ba20d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/modelaudit-picklescan/CHANGELOG.md
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from 41d37ba to 903a0a7 Compare September 30, 2026 08:08

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 91ef99c3c6

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md
Comment thread packages/modelaudit-picklescan/CHANGELOG.md
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from 91ef99c to 50a7d92 Compare September 30, 2026 09:20

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a9fc010f6c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread CHANGELOG.md Outdated
Comment thread tests/test_release_workflow.py Outdated
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 2 times, most recently from 3dfb6da to 1011d5a Compare October 1, 2026 23:56

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8030467788

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread CHANGELOG.md
Comment thread CHANGELOG.md
Comment thread CHANGELOG.md
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from 8030467 to 190afa7 Compare October 3, 2026 00:02
@mldangelo-oai mldangelo-oai changed the title chore: release main chore(main): release 0.2.53 Oct 3, 2026
@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex review

Please review the current head 4352cee5e878c50c7d8d1b7a2fc0213326e8374b against main 2e785193c2fbbaf6ef6c9442a19c7576b36dde9b, including the scanner dependency floor, both package release metadata and changelog accuracy. The body now preserves the canonical Release Please framing and component labels; its actual published readback passes the workflow-pinned parser and full Manifest proof for both releases.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 4352cee5e8

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4352cee5e8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/test_dependency_lock.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex review

Please review current head 2818eee523917f4f4c3d3fe791defd92d4bec625 against main 2e785193c2fbbaf6ef6c9442a19c7576b36dde9b. This follow-up addresses the dependency-interval finding from review 5398209423: the guard now requires explicit lower and upper bounds and checks their parsed versions, while preserving supported future floor increases. Independent fixtures reject both reported unsafe ranges, old/prerelease floors, an inclusive upper bound and an incompatible locked version; current and coherent future requirements pass.

The package requirement and runtime are unchanged. Fresh native and independent reviews are clean; the PR body records validation and the reproduced baseline local cache-staging limitation.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 2818eee523

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 2818eee523

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@mldangelo-oai mldangelo-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the exact release head against main 2e78519. The dependency floor, explicit interval regression guard, both package versions and release notes are consistent. Fresh native and independent reviews are clean; both current-head repository Codex reviews are clean, and all review threads are resolved.

All 43 current-head checks passed, with two expected skips. The relevant regression and both locally failing CLI nodes are selected in successful CI lanes. Local full-suite failures remain documented as a reproduced baseline cache-staging limitation, not a local suite pass. Published release metadata is verified against the workflow-pinned parser and full Manifest for both intended releases.

Approved for the ordinary squash merge and existing release workflow; no bypass or manual publication.

@mldangelo-oai
mldangelo-oai merged commit 01273a4 into main Oct 3, 2026
45 checks passed
@mldangelo-oai
mldangelo-oai deleted the release-please--branches--main branch October 3, 2026 02:08
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant