Skip to content

chore(deps): Update dependency intel/gmmlib to v22.10.1 - #1184

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/dev-image-pinned-deps
Closed

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/dev-image-pinned-deps

Conversation

@renovate

@renovate renovate Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
intel/gmmlib patch 22.10.0 → 22.10.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

intel/gmmlib (intel/gmmlib)

v22.10.1

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Vienna)

  • Branch creation
    • "before 6am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from lusoris as a code owner September 2, 2026 09:55
@lusoris
lusoris marked this pull request as draft September 2, 2026 10:42
@lusoris

lusoris commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Parked as draft — this bump cannot land alone.

Dev Container Build + Smoke Test fails at the NEO layer (step #19) with curl: (22) The requested URL returned error: 404: the Containerfile downloads intel-igdgmm12_${GMMLIB_VER} from the intel/compute-runtime release page for NEO_VER=26.31.39395.13, and that release bundles gmmlib 22.10.0, not 22.10.1. gmmlib/IGC/NEO/Level-Zero move as a matched set; bumping one ARG in isolation produces a URL that does not exist.

(The kernel source directory … linux-6.17.0-1022-azure line earlier in the log is a non-fatal intel-oneapi-vtune dkms warning — the passing sibling run #1137 logged the same line.)

Follow-up in flight: a Renovate rule to group intel/gmmlib with intel/compute-runtime, intel/intel-graphics-compiler and oneapi-src/level-zero into one PR, and a matched-set bump to the current NEO release.

🤖 Generated with Claude Code

lusoris added a commit that referenced this pull request Sep 2, 2026
…NEO stack as a set

Two train PRs could never merge, for reasons Renovate cannot know:

- #1183 digest-pinned slsa-framework/slsa-github-generator. The generator's
  README says its reusable workflows MUST be referenced by an exact @vX.Y.Z
  tag so slsa-verifier can verify the trusted builder (hash-pinned reusable
  workflows are unsupported, slsa-verifier#12), and the Release Script
  Contract check (scripts/release/tests/test-publication-environment-binding.sh)
  enforces the tag form. pinDigests: false for that package; tag bumps still
  flow.

- #1184 bumped intel/gmmlib alone. dev/Containerfile fetches
  libigdgmm12_${GMMLIB_VER} and the IGC debs from the intel/compute-runtime
  release page for NEO_VER, so a lone gmmlib bump yields a 404 in the
  Dev Container Build. compute-runtime, intel-graphics-compiler, gmmlib and
  level-zero are now one Renovate group; manual review stays (ADR-0605).

Verified: renovate.json parses; the untouched release-contract validator
still passes on master's tag-form supply-chain.yml.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@lusoris

lusoris commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Superseded by #1191, which bumps NEO/IGC/gmmlib/Level-Zero as a matched set (lone gmmlib bumps 404 — see the comment above). Renovate will regroup these via #1188.

@lusoris lusoris closed this Sep 2, 2026
@renovate

renovate Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (22.10.1). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate
renovate Bot deleted the renovate/dev-image-pinned-deps branch September 2, 2026 14:51
lusoris added a commit that referenced this pull request Sep 2, 2026
…NEO stack as a set (#1188)

* chore(renovate): never digest-pin the SLSA generator; bump the Intel NEO stack as a set

Two train PRs could never merge, for reasons Renovate cannot know:

- #1183 digest-pinned slsa-framework/slsa-github-generator. The generator's
  README says its reusable workflows MUST be referenced by an exact @vX.Y.Z
  tag so slsa-verifier can verify the trusted builder (hash-pinned reusable
  workflows are unsupported, slsa-verifier#12), and the Release Script
  Contract check (scripts/release/tests/test-publication-environment-binding.sh)
  enforces the tag form. pinDigests: false for that package; tag bumps still
  flow.

- #1184 bumped intel/gmmlib alone. dev/Containerfile fetches
  libigdgmm12_${GMMLIB_VER} and the IGC debs from the intel/compute-runtime
  release page for NEO_VER, so a lone gmmlib bump yields a 404 in the
  Dev Container Build. compute-runtime, intel-graphics-compiler, gmmlib and
  level-zero are now one Renovate group; manual review stays (ADR-0605).

Verified: renovate.json parses; the untouched release-contract validator
still passes on master's tag-form supply-chain.yml.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* ci(go): take the toolchain version from go.mod, not a literal pin

go-ci.yml pinned go-version: "1.27.0" while go.mod's directive is what
Renovate bumps, and GOTOOLCHAIN=local forbids auto-download — so #1139
(go 1.27.0 -> 1.27.1) failed go vet + go test with:

  go: go.mod requires go >= 1.27.1 (running go 1.27.0; GOTOOLCHAIN=local)

Every setup-go step now uses go-version-file: go.mod. actionlint finding
count unchanged vs master.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* docs(changelog): regenerate the Unreleased block from changelog.d/

scripts/release/concat-changelog-fragments.sh --check (Release Script
Contract, ADR-1128) fails when a fragment is added without re-rendering
CHANGELOG.md. Rendered with --write, not hand-edited (ADR-0221).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant