Skip to content

build(deps): pin cloud-commitments-go to ce951361 - #2115

Merged
cristim merged 1 commit into
mainfrom
build/repin-cloud-commitments-go-ce951361
Sep 28, 2026
Merged

cristim merged 1 commit into
mainfrom
build/repin-cloud-commitments-go-ce951361

Conversation

@cristim

@cristim cristim commented Sep 28, 2026

Copy link
Copy Markdown
Member

Updates all four cloud-commitments-go modules from c5cf5c7fbad8 to ce951361290141aa53b528dfce862fbc22a1d01b. This adopts cache-engine deduplication, resolved-address metadata blocking, and nullable total purchase costs from library PRs #149, #148, and #151.

The CLI forwards PurchaseResult without reading Cost, so no source migration is needed. Only go.mod and go.sum change; the selected transitive module versions remain identical.

Validation on macOS with Go 1.26.6 and GOWORK=off:

  • go test -race -short ./...: passed (406.408s).
  • Race-enabled tests for shared common/httpclient packages and AWS EC2, RDS, ElastiCache, MemoryDB, Redshift, and Savings Plans packages: passed.
  • CLI build and --help, go vet ./..., golangci-lint 2.10.1, go mod verify, and go mod tidy -diff: passed.
  • go version -m confirms all four target modules in the built executable. Pre-commit hooks passed.

Purchase, CSV, audit, and provider behavior checks use offline fixtures and mocks. No cloud purchase was attempted. No new CLI logic or regression test is introduced by this dependency-only change.

Independent review: gpt-6-astra reviewed final commit 4a374255457060799d580ae9a3c447dae7f72b60 with no actionable findings and approved merge once required CI is green. The reviewer independently passed focused race tests, build, help, vet, lint, module verification, and tidy checks. The session explicitly approved this reviewer in place of unavailable Opus 5.5.

@cristim cristim added triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm urgency/this-sprint Within the current sprint impact/many Affects most users effort/s Hours type/chore Maintenance / non-user-visible labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

  • Run on-demand review

This review includes 1 billable file and costs up to $0.25.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 8 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 64 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: LeanerCloud/cloud-commitments-cli/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: f141d460-5ec9-429c-8678-425b6c79411b

📥 Commits

Reviewing files that changed from the base of the PR and between 3b07983 and 4a37425.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

CLI re-pin independent review

Verdict: MERGE once required CI is green, reviewed SHA 4a374255457060799d580ae9a3c447dae7f72b60. Two independent diff passes and final-SHA review: no actionable findings.

Reviewer: gpt-6-astra, session-authorized substitute, not an Opus review. Read-only author checkout; reviewer clone /Users/cristi/.claude/worktrees/cudly-resume-20260929/review-cli-repin, detached at reviewed SHA and clean. Verified all tracked committed files match the independently tested snapshot before checkout.

Reviewed diff SHA-256 89fb5190b746c5344f06eb65a7617011f51e55b34ca4653ed59485ea13e11e5f against base 3b079831fe94d1f6d69f20a2ff59a916ed450f19. Exactly go.mod/go.sum, four module pins plus corresponding checksums. All target modules resolve to ce951361290141aa53b528dfce862fbc22a1d01b, with no replaces or transitive version changes.

Traced purchase forwarding, dry-run result, audit construction and CSV fields. CLI never accesses PurchaseResult.Cost directly; changing recommendation-based report semantics would exceed scope. No new CLI regression test is needed for the pure dependency change. Checked nullable-cost and assertion-invariant memories.

Independent verification with GOWORK=off GOTOOLCHAIN=go1.26.6 and per-repo locks:

Check Result
go list -m -json four selected modules Exit 0, exact target versions/checksums, no Replace
go mod verify Exit 0
go mod tidy -diff Exit 0, empty diff
Focused `go test -race -short ./cmd -run '^(TestExecutePurchase TestCreateDryRunResult
go vet ./... Exit 0
go build -o <review-binary> ./cmd, then binary --help Both exit 0
go version -m reviewer binary All four exact target dependencies embedded
Author full-suite log, independently read cmd passed in 406.408s; author execution, not reviewer execution
Exact lint 2.10.1 built with Go 1.26.6 Independent exit 0, zero issues
Eight planned upstream smoke package logs Independently read, all pass; author execution

No purchase, deployment, real-cloud CSV execution, or GitHub mutation. Consumer tests use mocked cloud boundaries; binary help proves executable startup, not live purchase correctness. Publication and required CI remain pending; parent owns the exact-SHA CI gate. Any new commit invalidates this verdict.

@cristim
cristim merged commit 1417914 into main Sep 28, 2026
12 checks passed
@cristim

cristim commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

CLI #2115 post-merge verification

Verified merged main 14179147d3a9c6d89777412de0ffcf4b3e97380a in the isolated cli-repin clone. Tracked tree is identical to reviewed commit 4a374255457060799d580ae9a3c447dae7f72b60; git diff --stat <reviewed> HEAD is empty. Clone and branch preserved; checkout is detached at the merged SHA and clean.

All Go commands use GOWORK=off GOTOOLCHAIN=go1.26.6.

Command Exit Result
go list -m -json for all four cloud-commitments-go modules 0 Same target versions/checksums, no replaces; JSON identical to approved snapshot
go mod verify 0 all modules verified
go test -race -short -count=1 -timeout=15m ./cmd -run '^(TestLoadRecommendationsFromCSV|TestLoadRecommendationsFromCSV_FileErrors|TestCreateDryRunResult|TestRunToolFromCSV|TestRunToolFromCSV_WritesAuditRecordsOnDryRun)$' 0 cmd passed, 14.096s
go build -o <evidence>/cudly-postmerge ./cmd 0 Built merged source
<evidence>/cudly-postmerge --help 0 Help emitted
go version -m <evidence>/cudly-postmerge 0 Four ce951361 module pins, vcs.revision=14179147d3a9c6d89777412de0ffcf4b3e97380a, vcs.modified=false

Tests exercise actual CLI CSV parsing and dry-run orchestration with offline fixtures and mocked cloud boundaries. No real cloud purchase is claimed. The full 406-second suite was not repeated because the merged tracked tree is identical. Parent owns post-merge CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/many Affects most users priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/chore Maintenance / non-user-visible urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant