Skip to content

build(deps): bump aiohttp from 3.14.1 to 3.14.3 - #758

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/aiohttp-3.14.3
Closed

build(deps): bump aiohttp from 3.14.1 to 3.14.3#758
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/aiohttp-3.14.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps aiohttp from 3.14.1 to 3.14.3.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Summary by CodeRabbit

  • 개선 사항
    • 애플리케이션 실행 환경의 구성 요소를 최신 안정 버전으로 업데이트했습니다.
    • 관련 검증 정보를 함께 갱신해 배포 및 설치 과정의 일관성과 신뢰성을 높였습니다.

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 4, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 4, 2026 22:40
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 4, 2026
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

requirements-strix-ci-hashes.txtaiohttp 버전을 3.14.3으로 업데이트하고 새 버전의 해시 목록으로 교체했습니다.

Changes

aiohttp 버전 및 해시 업데이트

Layer / File(s) Summary
aiohttp 버전 및 해시 교체
requirements-strix-ci-hashes.txt
aiohttp 버전을 3.14.1에서 3.14.3으로 변경했습니다. 새 버전에 해당하는 패키지 해시를 반영했습니다.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: seonghobae

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 aiohttp를 3.14.1에서 3.14.3으로 업데이트하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/pip/aiohttp-3.14.3

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@requirements-strix-ci-hashes.txt`:
- Around line 7-126: requirements-strix-ci.txt에 aiohttp==3.14.3을 추가해 소스 입력을 고정한
뒤, 파일 상단에 명시된 정확한 uv pip compile 명령을 실행하여 requirements-strix-ci-hashes.txt를
재생성하세요.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e14eb536-cba0-4adc-82ce-b24ba07a81fd

📥 Commits

Reviewing files that changed from the base of the PR and between 3f65dbe and ae68698.

📒 Files selected for processing (1)
  • requirements-strix-ci-hashes.txt

Comment on lines +7 to +126
aiohttp==3.14.3 \
--hash=sha256:03cd2bde3d7f085b64e549c985f4bb928cad7e8ecf5323bfca320db548d81b39 \
--hash=sha256:041badb8f84396357c4d3ad26de6afd7a32b112f43d3c63045c0c8278cfd2043 \
--hash=sha256:0a5ff2dfbb9ce645fa5b8ef3e02c6c0b9cc3f6030ff863d0c51fffc50cb5541b \
--hash=sha256:0fdea2281997af69da84c77ffa6f5938a0285f21fb3887c249d67419ca865b3d \
--hash=sha256:11fb37ef075669eee52ab1928fbf6e1741fada40409fa309ebde9607a962aebf \
--hash=sha256:134ac5ddcf61c6fad984b9a5727d83492ada43d63471db20fb73042c13fca62f \
--hash=sha256:152516815ef926786a0b6ae2b8f1fd2e0c71582dee0b435636865316fd4891b7 \
--hash=sha256:1576145bdceeb92382d899751e12743a3a5b8e460a841e3e50543859e54864dc \
--hash=sha256:16100ad3ab8d649fdfbee87602d9d2dcdca9df0b9eda8a1b5fdc0d41f96da559 \
--hash=sha256:16ea7e24c309fb7c0bbd505d149abe4fe4dccfb8db911db7dbec0921bc889a6f \
--hash=sha256:18c441d0a8fca6de8d1f546849b9f0ab20d435993e2c5b59562b2fae6be2f929 \
--hash=sha256:18cb43369747b2ae007bd2655fb8e63a099c2ff1d207962943636dac989b3147 \
--hash=sha256:1b59533861b70a2185c8f4f350f791f39d64358ef6944ce71c5240c9ec0982c9 \
--hash=sha256:1c5281acc88b92396f88c7e1e2748f8466689df22b80170e4f51efa712fb47a8 \
--hash=sha256:1c5ec8fb1bcc31a8466f74aaf26c345d5c386fa4bd08a3f0eb9c7a4a3fe8b5bf \
--hash=sha256:1caa7b0d05f3e3a36f87788c59e970a7ee1cefcfcbb924a9f138c4a6551c9cb7 \
--hash=sha256:21c016079415ed3fd676963e9793700a566d85dbbd6bfc564b9b2d209147dcc8 \
--hash=sha256:2498f0fe69ead802f9675beca44a7c21c62fdaa4ec5145ea1c3ad6edbee29f85 \
--hash=sha256:25bd2708db6bdf6a6630dd37bdcdfcb47c4434d22ac69c64665b802910140b30 \
--hash=sha256:270d3dace9ca2f10f0da5d8ebe519b7a310fc6112ed916e32df5866df0888553 \
--hash=sha256:2e1161602f45a54de2ce0905243a95f58cb42dcd378402f3697f5e0b21e9d2e7 \
--hash=sha256:2e9878ae68e4a5f1c0abe4dd497dbc3d51946f5837b56759e2a02e78fa90ef86 \
--hash=sha256:30402d03a7c0ff52bce290b57e564e9079fd9d0cb545c8aba73f86a103162d2e \
--hash=sha256:33a2d7c28d33797a2e99923dffa63f83d908a19b6bf26cfe80fa790aa5e1a75a \
--hash=sha256:362a3fd481769cac1a824514bcd86fda51c65e8fe6e051099e008fddde6db17c \
--hash=sha256:38901a84da3ce22249f6e860bf8f90d141bcab7da090cc398f8bb58c0e44b7da \
--hash=sha256:39aded8c7f3b935b54aab1d8d73c70ec0ee2d3ec3b943e0e86611bc150ba47f5 \
--hash=sha256:3a26434dafe408229ff3403458ca58de24fb51936504decac49ce6755f77e59d \
--hash=sha256:3ae5b3a59436d089b5395d910121a390feed4d00578eb95a0fd1a329fe963100 \
--hash=sha256:3d4f72af88ac2474bb5bca640030320e3d38a0163a1d7533500e87be458eef71 \
--hash=sha256:3f42e9b78301f11c8f861746175d8b9c1ccef713fcad9eab396e2f6db8ed4a22 \
--hash=sha256:42a67efc36300d052fb4508a53e8b6901b9284b599ae63945c377569c5fcc1e1 \
--hash=sha256:48d67b87db6279c044760787eb01f6413032c2e6f3ba1cafaa492b1c8e578479 \
--hash=sha256:498c6c623134f8e09a3c4e60bcd607a0b4590dd7dbf08dd40851b27cbb520ccb \
--hash=sha256:49f7325beb0f85ef4aef5f48f490269575f83e6e2acad00a1d80b807eb027062 \
--hash=sha256:4e3ac92d90e92773b2362d506068e9a948192bd553e743c5b2429e28527c8661 \
--hash=sha256:530125ee1163c4219af35dc3aa1206e541e7b31b6efc1a3f93b70a136f65d427 \
--hash=sha256:5373dc80ad1aa2fb9ad95c83f24eef418bbda3a61375f128e5b0192e4f3f9b32 \
--hash=sha256:53e5179d8abb5710f8e83ba207c41c8d1261fcffd4616500e15ca2b7a33be10a \
--hash=sha256:53e7b4ce82b54a8bcc71b3b67a5cbd177ca1d7f592cbc92cd38b7349f73482db \
--hash=sha256:543906c127fb1d929b95076db19b83fa2d46751006ff1e23b093aa5ac4d8db42 \
--hash=sha256:54cfcdee2770dac994417cbb0ee1f3eb0e7cb6b30c79bf44f2c02ff79ec5124a \
--hash=sha256:55bdcc472aafe2de4a253045cc128007a64f1e0264fb675791e132ea5edaa3bd \
--hash=sha256:56f355e79f71aef2a85c80305cc915f894b170dba76de5fe84f6351939b83c06 \
--hash=sha256:5895ef58c4620afe02fa16044f023dc4dafec08158f9d08874a46a7dbc0341b8 \
--hash=sha256:5bcb6ff3fdab1258a192679ff1a05d44f59626430aa05cd1a9d2447423599228 \
--hash=sha256:5f08ec777f35ee70720233b8b9811d3bb5d728137f30ac91b7457709c3261ac0 \
--hash=sha256:614c61d478b83953e261d02bb2df750f17227cd33ef8002945bf5aebbde21919 \
--hash=sha256:617105e2c3018ee38d0c8ce5ee3c84f621a6d8b9f723202aacaff28449ca91ee \
--hash=sha256:6debfa7312ff9d4c124dc71d72e9a0a4b9e0879e48ba6fcb42bef5c3300289e2 \
--hash=sha256:7041d52c3a7fa20c9e8c182b534704abb19502c8bdcbde7ab23bfda6f642394f \
--hash=sha256:70c987b27534f9ae1a723f47ae921571d616da21d3208282bf4c52af5164ac43 \
--hash=sha256:74ab5b6a9fb13e873e5a90946588baecaf488745e1db1a4a5c433f971f035098 \
--hash=sha256:78253b573e6ffab5028924fc98bc281aae05445969982a10864bc360dea2016c \
--hash=sha256:7a75aa63cbf9b21cfaf60dc2657e19df2c2867d91707d653fee171ffeedd1371 \
--hash=sha256:8800c996b01c2772a783e3e46f3e1abd5823029adca0df54231960de9bfefa5b \
--hash=sha256:89176250f686cb9853c0fb7ead90e639e915b84a6f43eedc2a4e7ec21f1037f0 \
--hash=sha256:8a5fd34f7f7410d1730d5c2ba873cacb2eed3fede366feb268a70ba22581ed8f \
--hash=sha256:8b3b60de05f3dcb6f6a00f818bb2ec781cee4de0645f59ccaf99b1d1823b6100 \
--hash=sha256:8f2f1c4c032c7cedd7d8da6f54c97b70266c6570c3108d3fdffee7188bb70529 \
--hash=sha256:9491196535a88924a60afd5b5f434b5b203b6cc616250878dbdb223a8f7844bc \
--hash=sha256:9aa6e61fdf20105c4144e755bd586008ff450791d67b1c8146fdc15959c4d51c \
--hash=sha256:9d9edccfe496b476db5f398d97b865e9a6752bcf8aec4eef8390ce20fb64bb41 \
--hash=sha256:9fc7b5bfec6573f3ae844f457fdde5adeb713f8b8e4a81ad64fc207b49383716 \
--hash=sha256:a0dc483c00da8b673abbb367eb6f8d8f4bcec30eb58529ea13cb42e7fd2dfa33 \
--hash=sha256:a3a8296e7ab5c295f53f1041487cb088e1480775aafbf7fe545d93b770a0f96f \
--hash=sha256:a3e22975f905b89a55a488c2a08f2fdb2186175349e917d48985cc468a3d4c6e \
--hash=sha256:a4af35c443e0b1a1bd6a8af3f3485d7fda15c142751a00f3ff8090f0b93346fa \
--hash=sha256:a94dbaae5ae27bd849c93570669bff91e0510f33a80805738e3de72a7be0447b \
--hash=sha256:ac74facc01463f138b0da5580329cfcc82818dea5656e83ddcd11268fc12ff80 \
--hash=sha256:ad4c8b7488d745d2ca4838ebd8ae5ba9b56341d30b1da43640e4ce87f9f49646 \
--hash=sha256:b014a6ed7cf912e787149fdc529166d3ceabac23f26efeea3158c9aba2354e7e \
--hash=sha256:b20032766aedf6261c7a566585a40867d092ac03a0d81592d5370ef9b054f99b \
--hash=sha256:b2466434105a4e03113c36ec775cc2ebe6676b62eae326fa670bb607ef788c1c \
--hash=sha256:b304db572b4368edd8dda8a2274f73156fe15558fca4a917cb8a09fc47af5963 \
--hash=sha256:ba59d59aba08ac02fc03b0c8983ccd5ee39a199d0552ce9e6d2b4845b34d59ae \
--hash=sha256:bd52f811e65f6fb634b1047159657c98f52b407f8efec907bcfc09da9a4c0a25 \
--hash=sha256:bdd0e2834dce1a26c1bbe26464861e16bbe217042cbff619247c11594472518c \
--hash=sha256:c23ec8ee9d5ab2f5421f9c7fffce208435607af27fd46d4a44e031954352838f \
--hash=sha256:c39846c3aad97a8530c89d7a3869a8f8e9e3762c6ac0504481e5c80948f7e807 \
--hash=sha256:c3c200cf9757edd785051dc699c7ecbec22110dbfcb3fefc7a9f9695eda8ea7a \
--hash=sha256:c7d3a97c678d34fc5b59da671ee9cd630096ddc643e7b5a30d54a2a6f3574d3f \
--hash=sha256:c8653fd547c93a61aadc612007790f5555cdd18946fa48cf45e26d8ea4ea473d \
--hash=sha256:cc7cb243a68167172f48c1fd43cee91ec4b1d40cefd190edd43369d1a6bc9c82 \
--hash=sha256:ccd4893707b3e2a13e39c90d43cf80edf2e4d0457935bcc103bf2346214c3f15 \
--hash=sha256:cd817772b2fcf2b8c0905795318485f9ec16eae60b29feb7f4c77085311637f0 \
--hash=sha256:cda5fd5c95ad7a125a2e8464acc78b98b94c475a3780d6aa0aa157c93f470f4d \
--hash=sha256:cef89a58e628c4efcac3275c2d68083f82426dcdc89c1492a6f654f9f7ea6ab9 \
--hash=sha256:d1558173930a5a8d3069cee5c92fc91c87c4dbcb099debbb3622053717145a19 \
--hash=sha256:d6088ec9894113802bddb3c09e974929aed2c7b3a8c456219b8aab4481f1a239 \
--hash=sha256:d6218d92e450824e9b4881f44e8c09f1853b490f9a64130801024a4793b1b3b0 \
--hash=sha256:d77640cc618c1d99fc4f8589c0f24a730adfa54eb1e57ef7bf0c8dfb78da898c \
--hash=sha256:d7d2deec16eeedf55f2c7cf75b521ea3856a5177e123844f8fd0f114ce252cb5 \
--hash=sha256:db332af25642007330fca8be5c4d194caf2bea7a7fc84415aff3497af5dfee6b \
--hash=sha256:dd54d0e8717de95939766febac482ac0474d8ac3b048115f9f2b1d23a16e7db4 \
--hash=sha256:ddcac3c6b382e81f1dd0499199d4136b877beb4cb5ef770bbbfba56c4b8f55d2 \
--hash=sha256:df82f3787c940c94986b34222d59c9e38843fba85139f36e85255a82ad5355a9 \
--hash=sha256:dfa68deb2a443bdaa3ea5297b0699c1464f08aef3812b486d1348eee61b07dc0 \
--hash=sha256:dff9461ec275f22135650d5ba4b4931a11f3958df7dfbb8db630000d4dee0883 \
--hash=sha256:e1e74298bab6ee0d6e749ed4fd1901c7e604bdda32c03d787a2cc71c46d0433d \
--hash=sha256:e2667f0bbe7eb6c74eae5e9691441ad186e5845ca3cff63230fc09c4e7514f5d \
--hash=sha256:e3be98a7c30b8c25d573dafba7171d66dfb05ee6a9070fc46535464ff97700a6 \
--hash=sha256:e568e14940c09955aa51f4e645b6daa18a581c5dcfcd73744dcc86a856e3ced3 \
--hash=sha256:e72ee89e28d907a18f46959b4eb0bb06701cc7f8cf4366e00029e2ccfaaf5924 \
--hash=sha256:e92eb8acc45eb6a9f4935071a77edf5b85cc6f8dfad5cd99e97653c26593cdde \
--hash=sha256:ea05e1f97ceea523942d9b2a7d7c0359d781d683d6b043f5943a602b14da4787 \
--hash=sha256:eac645b09bcfdf73df7536331f0678c1086ea250981118ddb5199e17ccef72bb \
--hash=sha256:eb0495d778817619273c108784292be161a924b9f5ae5cbbc70a2caa6838250b \
--hash=sha256:ebe8e504f058fe91223351cecd2d9d6946c9d241bb0250d898ffbdf584cc72b0 \
--hash=sha256:ed099d105449c4f9e84f24af203cd131349d4761d8813fa7e02c32e7128cd910 \
--hash=sha256:f0f177d1b195b9e06376cfd7d308d8a1b920909a609d03ac82a8c73bbb16d3b9 \
--hash=sha256:f3d2669fe7dec7fc359ecdb5984b29b50d85d5d00f8c1cb61de4f4a24ee42627 \
--hash=sha256:f4e05329faa0ea1a404b37de4f034fd2c2defcca06a68dc6745e4e56c88e8a48 \
--hash=sha256:f53bcd52f585e1ac3e590d61434eb61f9a88c38df041b4ea126d97144344a77b \
--hash=sha256:f55119f7bf25f49ed210f6096090715da24f2943c62102448915fde3c62877ce \
--hash=sha256:f631fe87a6f30df5fbe6d79640b25e4cffb38c31c7fb6f10871517b84b0f8c1a \
--hash=sha256:f8fb78a83c9e5f741ca3a68cfb455c1f5bb83b4e7249a3848b3cd78d0a8563b0 \
--hash=sha256:fa9467a8113aa69d3d7c55a70ef0b7c636010a40993f3df9d9d0d73b3eb7ef24 \
--hash=sha256:fd51ebf9d3a00c074df4ede271023f4d2dba289bcc740b88191872716014e3c5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

lock='requirements-strix-ci-hashes.txt'

mapfile -t inputs < <(
  fd --type f --glob 'requirements-*-ci.txt' . |
  rg -v -- '-hashes\.txt$'
)
test "${`#inputs`[@]}" -gt 0

# non-hash 입력 파일과 생성 명령을 확인합니다.
rg -nP '^\s*aiohttp==3\.14\.3(?:\s|$)' "${inputs[@]}"
rg -n 'uv pip compile' "${inputs[@]}" "$lock"

pypi_json="$(mktemp)"
lock_hashes="$(mktemp)"
pypi_hashes="$(mktemp)"
trap 'rm -f "$pypi_json" "$lock_hashes" "$pypi_hashes"' EXIT

curl -fsSL 'https://pypi.org/pypi/aiohttp/3.14.3/json' > "$pypi_json"

awk '
  /^aiohttp==3\.14\.3 / { in_aiohttp=1; next }
  in_aiohttp && /^[A-Za-z0-9_.-]+==/ { exit }
  in_aiohttp { print }
' "$lock" |
sed -n 's/.*--hash=sha256:\([0-9a-f]\{64\}\).*/\1/p' |
sort -u > "$lock_hashes"

jq -r '.urls[].digests.sha256' "$pypi_json" |
sort -u > "$pypi_hashes"

diff -u "$pypi_hashes" "$lock_hashes"

Repository: ContextualWisdomLab/.github

Length of output: 217


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

echo '--- requirement files ---'
git ls-files '*requirements*' | sort

echo '--- aiohttp declarations and compile commands ---'
rg -n -C 2 'aiohttp|uv pip compile' --glob 'requirements-*.txt' --glob '!requirements-*-hashes.txt' --glob 'requirements-*-hashes.txt' .

echo '--- changed files ---'
git status --short
git diff --stat -- requirements-strix-ci-hashes.txt requirements-strix-ci.txt
git diff --unified=3 -- requirements-strix-ci-hashes.txt requirements-strix-ci.txt

echo '--- lock metadata ---'
sed -n '1,18p' requirements-strix-ci-hashes.txt
rg -n -C 2 'uv pip compile|requirements-strix-ci' requirements-strix-ci-hashes.txt .github 2>/dev/null || true

Repository: ContextualWisdomLab/.github

Length of output: 13055


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

echo '--- source input ---'
nl -ba requirements-strix-ci.txt | sed -n '1,220p'

echo '--- all aiohttp references in tracked requirement/config files ---'
rg -n -i 'aiohttp' --glob 'requirements-*.txt' --glob '*.yml' --glob '*.yaml' --glob '*.sh' .

echo '--- lock package block boundaries ---'
python3 - <<'PY'
from pathlib import Path
p = Path("requirements-strix-ci-hashes.txt")
lines = p.read_text().splitlines()
for i, line in enumerate(lines):
    if line.startswith("aiohttp=="):
        start = i
        end = next((j for j in range(i + 1, len(lines)) if j and "==" in lines[j] and not lines[j].startswith((" ", "#"))), len(lines))
        print(f"lines {start + 1}-{end}:")
        print("\n".join(lines[start:end]))
        break
else:
    raise SystemExit("aiohttp block not found")
PY

echo '--- PyPI hash comparison ---'
python3 - <<'PY'
import json
import urllib.request
from pathlib import Path

data = json.load(urllib.request.urlopen("https://pypi.org/pypi/aiohttp/3.14.3/json"))
pypi = {u["digests"]["sha256"] for u in data["urls"]}

lines = Path("requirements-strix-ci-hashes.txt").read_text().splitlines()
start = next(i for i, line in enumerate(lines) if line.startswith("aiohttp==3.14.3"))
end = next((j for j in range(start + 1, len(lines))
            if "==" in lines[j] and not lines[j].startswith((" ", "#"))), len(lines))
lock = {
    line.split("sha256:", 1)[1]
    for line in lines[start:end]
    if "--hash=sha256:" in line
}
print(f"PyPI hashes: {len(pypi)}")
print(f"Lock hashes: {len(lock)}")
print("missing_from_lock:", sorted(pypi - lock))
print("extra_in_lock:", sorted(lock - pypi))
PY

Repository: ContextualWisdomLab/.github

Length of output: 226


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

echo '--- source input ---'
awk '{printf "%6d\t%s\n", NR, $0}' requirements-strix-ci.txt | sed -n '1,220p'

echo '--- all aiohttp references ---'
rg -n -i 'aiohttp' --glob 'requirements-*.txt' --glob '*.yml' --glob '*.yaml' --glob '*.sh' . || true

echo '--- lock package block and hash comparison ---'
python3 - <<'PY'
import json
import urllib.request
from pathlib import Path

lock_path = Path("requirements-strix-ci-hashes.txt")
lines = lock_path.read_text().splitlines()
start = next(i for i, line in enumerate(lines) if line.startswith("aiohttp=="))
end = next(
    (j for j in range(start + 1, len(lines))
     if "==" in lines[j] and not lines[j].startswith((" ", "#"))),
    len(lines),
)
block = lines[start:end]
print("\n".join(f"{i + 1}: {line}" for i, line in enumerate(block, start)))
lock_version = block[0].split("==", 1)[1].split()[0]
lock = {
    line.split("sha256:", 1)[1]
    for line in block
    if "--hash=sha256:" in line
}
print(f"lock_version={lock_version}")
print(f"lock_hashes={len(lock)}")

data = json.load(urllib.request.urlopen("https://pypi.org/pypi/aiohttp/3.14.3/json"))
pypi = {u["digests"]["sha256"] for u in data["urls"]}
print(f"pypi_hashes={len(pypi)}")
print("missing_from_lock=", sorted(pypi - lock))
print("extra_in_lock=", sorted(lock - pypi))
PY

Repository: ContextualWisdomLab/.github

Length of output: 13889


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

echo '--- repository history and parent diff ---'
git log --oneline -5
git diff --stat HEAD^ HEAD -- requirements-strix-ci.txt requirements-strix-ci-hashes.txt || true
git diff --unified=2 HEAD^ HEAD -- requirements-strix-ci.txt requirements-strix-ci-hashes.txt || true

echo '--- available resolver ---'
command -v uv || true
uv --version 2>/dev/null || true

echo '--- PyPI hash comparison via curl ---'
tmp_json="$(mktemp)"
trap 'rm -f "$tmp_json"' EXIT
curl -fsSL 'https://pypi.org/pypi/aiohttp/3.14.3/json' -o "$tmp_json"

python3 - "$tmp_json" <<'PY'
import json
import sys
from pathlib import Path

data = json.load(open(sys.argv[1]))
pypi = {u["digests"]["sha256"] for u in data["urls"]}

lines = Path("requirements-strix-ci-hashes.txt").read_text().splitlines()
start = next(i for i, line in enumerate(lines) if line.startswith("aiohttp=="))
end = next(
    (j for j in range(start + 1, len(lines))
     if "==" in lines[j] and not lines[j].startswith((" ", "#"))),
    len(lines),
)
lock = {
    line.split("sha256:", 1)[1]
    for line in lines[start:end]
    if "--hash=sha256:" in line
}
print(f"PyPI hashes: {len(pypi)}")
print(f"Lock hashes: {len(lock)}")
print("Missing from lock:", sorted(pypi - lock))
print("Extra in lock:", sorted(lock - pypi))
PY

Repository: ContextualWisdomLab/.github

Length of output: 38071


aiohttp 버전을 소스 입력에 고정한 뒤 hash 파일을 재생성하세요.

requirements-strix-ci.txt에는 aiohttp 선언이 없고, 이 변경은 생성된 hash 파일만 수정합니다. aiohttp==3.14.3을 non-hash 입력 파일에 추가한 뒤, 파일 상단의 정확한 uv pip compile 명령으로 hash 파일을 재생성하세요.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@requirements-strix-ci-hashes.txt` around lines 7 - 126,
requirements-strix-ci.txt에 aiohttp==3.14.3을 추가해 소스 입력을 고정한 뒤, 파일 상단에 명시된 정확한 uv
pip compile 명령을 실행하여 requirements-strix-ci-hashes.txt를 재생성하세요.

Source: Coding guidelines

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for ae68698a20d86cce59e771fe09698e500a31c7b8.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: ae68698a20d86cce59e771fe09698e500a31c7b8
  • Workflow run: 30957349100
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for ae68698a20d86cce59e771fe09698e500a31c7b8.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

Copy link
Copy Markdown
Contributor

Closing as superseded. The same aiohttp==3.14.3 remediation is already integrated with the regenerated canonical/hash lock, pip-audit evidence, runtime smoke test, and exact-head security checks in #759. Keeping both open would create duplicate dependency state and review/check load.

@seonghobae seonghobae closed this Aug 4, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant