Repository navigation
build(deps): update CrawlKit and Release Drafter - #261
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 5:47 PM ET / 21:47 UTC (Revision 18). ClawSweeper reviewWhat this changesUpdates Slacrawl’s shared CrawlKit library to 0.16.7 and both pinned Release Drafter actions to 7.9.0, refreshes module checksums, and adds release-note context. Merge readiness✅ Ready for maintainer review This remains a useful, focused dependency update that is absent from current main and v0.10.2. No actionable correctness or security defect was found; normal approval requirements govern landing. Priority: P3 Review scores
Verification
How this fits togetherSlacrawl uses CrawlKit for shared archive, configuration, and CLI services. Release Drafter separately reads repository configuration and pull-request metadata to apply labels and prepare draft release notes. flowchart TD
A[Slack archive operations] --> B[CrawlKit library]
B --> C[Slacrawl archive and CLI]
D[Pull request metadata] --> E[Release Drafter actions]
F[Repository configuration] --> E
E --> G[Labels and draft release notes]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Root-cause clusterRelationship: Members:
Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything. Technical reviewBest possible solution: Land the consolidated, SHA-pinned updates while retaining the existing toolchain, dependency graph, and workflow permission boundaries. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates dependencies rather than reporting broken behavior; pinned source and upstream compatibility checks establish its scope. Is this the best way to solve the issue? Yes: consolidating the duplicate updates into one small PR preserves existing configuration and immutable action pins without introducing a competing implementation. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 04cfc53efaa3. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (17 earlier review cycles; latest 8 shown)
|
|
Hold evidence:
This PR remains draft until that time. |
Refresh the dependency-only patch on current main. Co-authored-by: Peter Steinberger <steipete@gmail.com>
8f9ec83 to
9482eef
Compare
|
@clawsweeper re-review Head |
|
🦞👀 Re-review progress:
|
steipete
left a comment
There was a problem hiding this comment.
Approved: exact-head CI green and reviewed.
Update CrawlKit from 0.16.6 to 0.16.7 and both pinned Release Drafter actions from 7.7.0 to 7.9.0. This consolidates #264, #265 and #266 into Vincent Koc’s dependency PR and retains the Go 1.27.0 minimum and all indirect dependency versions.
Both updates satisfy the two-day cooldown. CrawlKit 0.16.7 has been available from the public Go module proxy since 2026-10-01T07:50:56Z. Comparing the 0.16.6 and 0.16.7 module ZIPs showed only the changelog and snapshot sidecar implementation/tests changed; Slacrawl does not import that package. Its GitHub Release remains absent after a signing failure, but Go consumers use the published module ZIP and checksum rather than signed CLI assets. Release Drafter 7.9.0 was published on October 2; both action paths exist and the workflow’s triggers and permissions are preserved.
Independent Codex review found no actionable P0–P2 findings. All components of
make checkpassed on AWS using Go 1.27.1, Node 26.10.0 and GoReleaser 2.18.2: module verification/tidy, formatting, vet, vulnerability and dead-code checks, workflow lint, full race suite, CLI/import/export smoke, and Darwin/Linux amd64/arm64 snapshot packaging. The initial smoke attempt rejected an untracked Crabbox bootstrap script; moving that task artifact outside the checkout restored clean build metadata, and smoke plus snapshot passed at the same exact commit. All required hosted checks passed at3502654ac695fb1ffc27317b2e0101099d375038: https://github.com/openclaw/slacrawl/actions/runs/37578788913.Co-authored-by: Vincent Koc vincentkoc@ieee.org
Landing hold: all required checks are green, but the normal squash merge is blocked by the base-branch approval policy. The branch requires an approving review and code-owner review for these dependency/workflow paths. No administrator override or ruleset change was used.