Skip to content

chore(renovate): never digest-pin the SLSA generator; bump the Intel NEO stack as a set - #1188

Merged
lusoris merged 3 commits into
masterfrom
fix/renovate-train-hygiene
Sep 2, 2026
Merged

lusoris merged 3 commits into
masterfrom
fix/renovate-train-hygiene

Conversation

@lusoris

@lusoris lusoris commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Two Renovate PRs in today's train could never merge, for reasons Renovate cannot know; this teaches it.

  1. chore(deps): Pin slsa-framework/slsa-github-generator action to f7dd8c5 #1183 digest-pinned slsa-framework/slsa-github-generator. Its README: the generators "MUST be referenced by tag in order for the slsa-verifier to be able to verify the ref of the trusted builder" (hash-pinned reusable workflows unsupported, slsa-verifier#12). The Release Script Contract check enforces the tag form. → pinDigests: false for that package; tag bumps still flow.
  2. chore(deps): Update dependency intel/gmmlib to v22.10.1 #1184 bumped intel/gmmlib alone. dev/Containerfile downloads libigdgmm12_${GMMLIB_VER} and the IGC debs from the compute-runtime release page for NEO_VER, so a lone bump 404s (curl: (22)), turning Dev Container Build red. → compute-runtime + intel-graphics-compiler + gmmlib + level-zero are one group. Manual review stays (ADR-0605).

Type

  • build / ci — tooling / infra

Checklist

  • Commits follow Conventional Commits.
  • make format && make lint is green locally.
  • Unit tests pass: meson test -C build.
  • If I touched any SIMD/GPU code path, I ran /cross-backend-diff and the worst ULP is ≤ 2.
  • If I touched a feature extractor with SIMD/GPU twins, I either updated every twin or listed the gap under "Known follow-ups" below.
  • If I added a new .c / .cpp / .cu / .h / .hpp, it has the appropriate license header.
  • If this is a breaking change, the commit message uses ! or BREAKING CHANGE: and the migration path is documented below.
  • If this PR adds an ADR, the ADR row lives in docs/adr/_index_fragments/.

Config-only; no source, test, or compute path touched.

Bug-status hygiene (ADR-0165)

  • docs/state.md updated in this PR with a row

no state delta: dependency-bot configuration only, no libvmaf bug opened or closed.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Cross-backend numerical results

Not applicable.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: trivial.
  • Decision matrix — no alternatives: only-one-way fix.
  • AGENTS.md invariant note — no rebase-sensitive invariants.
  • Reproducer / smoke-test command — pasted below under "Reproducer".
  • CHANGELOG fragment — changelog.d/changed/renovate-train-hygiene.md.
  • Rebase note — no rebase impact: renovate.json is fork-local.

Reproducer

python3 -c "import json;json.load(open('renovate.json'))"
bash scripts/release/tests/test-publication-environment-binding.sh   # untouched validator still PASSes on master's tag form

Known follow-ups

Breaking changes / migration

None.

🤖 Generated with Claude Code

lusoris and others added 2 commits September 2, 2026 16:48
…NEO stack as a set

Two train PRs could never merge, for reasons Renovate cannot know:

- #1183 digest-pinned slsa-framework/slsa-github-generator. The generator's
  README says its reusable workflows MUST be referenced by an exact @vX.Y.Z
  tag so slsa-verifier can verify the trusted builder (hash-pinned reusable
  workflows are unsupported, slsa-verifier#12), and the Release Script
  Contract check (scripts/release/tests/test-publication-environment-binding.sh)
  enforces the tag form. pinDigests: false for that package; tag bumps still
  flow.

- #1184 bumped intel/gmmlib alone. dev/Containerfile fetches
  libigdgmm12_${GMMLIB_VER} and the IGC debs from the intel/compute-runtime
  release page for NEO_VER, so a lone gmmlib bump yields a 404 in the
  Dev Container Build. compute-runtime, intel-graphics-compiler, gmmlib and
  level-zero are now one Renovate group; manual review stays (ADR-0605).

Verified: renovate.json parses; the untouched release-contract validator
still passes on master's tag-form supply-chain.yml.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
go-ci.yml pinned go-version: "1.27.0" while go.mod's directive is what
Renovate bumps, and GOTOOLCHAIN=local forbids auto-download — so #1139
(go 1.27.0 -> 1.27.1) failed go vet + go test with:

  go: go.mod requires go >= 1.27.1 (running go 1.27.0; GOTOOLCHAIN=local)

Every setup-go step now uses go-version-file: go.mod. actionlint finding
count unchanged vs master.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the fix/renovate-train-hygiene branch from c7f99fe to b892540 Compare September 2, 2026 14:48
@lusoris
lusoris marked this pull request as ready for review September 2, 2026 14:49
scripts/release/concat-changelog-fragments.sh --check (Release Script
Contract, ADR-1128) fails when a fragment is added without re-rendering
CHANGELOG.md. Rendered with --write, not hand-edited (ADR-0221).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@lusoris
lusoris merged commit 6280fd2 into master Sep 2, 2026
69 of 73 checks passed
@lusoris
lusoris deleted the fix/renovate-train-hygiene branch September 2, 2026 15:26
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
@lusoris lusoris added the type:chore Maintenance, no user-visible change label Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:chore Maintenance, no user-visible change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant