Skip to content

chore(deps): update dependency nvidia/openshell to v0.1.2 - #7763

Closed
renovate-fullsend[bot] wants to merge 1 commit into
mainfrom
renovate/openshell
Closed

renovate-fullsend[bot] wants to merge 1 commit into
mainfrom
renovate/openshell

Conversation

@renovate-fullsend

@renovate-fullsend renovate-fullsend Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
NVIDIA/OpenShell minor 0.0.116 → 0.1.2

Release Notes

NVIDIA/OpenShell (NVIDIA/OpenShell)

v0.1.2: OpenShell v0.1.2

Compare Source

OpenShell v0.1.2
Quick install
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | OPENSHELL_VERSION=v0.1.2 sh
What's Changed

Full Changelog: NVIDIA/OpenShell@v0.1.1...v0.1.2

v0.1.1: OpenShell v0.1.1

Compare Source

OpenShell v0.1.1
Quick install
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | OPENSHELL_VERSION=v0.1.1 sh
What's Changed

Full Changelog: NVIDIA/OpenShell@v0.1.0...v0.1.1

v0.1.0: OpenShell v0.1.0

Compare Source

OpenShell v0.1.0
Quick install
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | OPENSHELL_VERSION=v0.1.0 sh
What's Changed

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:34 AM UTC · Completed 3:45 AM UTC

Commit: 664c472 · View workflow run →

Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $1.58

@codecov

codecov Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@fullsend-ai-review fullsend-ai-review Bot added the risk/low PR risk: low label Sep 27, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Risk Assessment: low (1/5)

Details

Automated dependency version bump by Renovate modifying a single file under a protected path with small blast radius and low churn; unchanged from the prior risk assessment on this PR (anchored).

Previous run

Risk Assessment: low (1/5)

Details

Automated dependency version bump by Renovate modifying a single file under a protected path with small blast radius and low churn.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review

Findings

Info

  • [scope-authorization-implicit] .github/scripts/openshell-version.sh — Authorization inferred from the mechanical nature of this change (a value-only dependency version + SHA pin bump; the diff is a rebase of this same Renovate PR onto a newer upstream release, v0.1.1 → v0.1.2). The automated update pattern is explicitly authorized by renovate.json's openshell packageRule (grouping NVIDIA/OpenShell and its base image into one PR) paired with its postUpgradeTasks (scripts/renovate/update-openshell-sha.sh), which refreshes OPENSHELL_SHA from the GitHub API after each version bump. The new SHA (6648bd0c290efbc41ba131ee9831ee45cd431f94) was independently verified against NVIDIA/OpenShell's v0.1.2 tag via the GitHub API and matches exactly. No architectural review required.

  • [protected-path] .github/scripts/openshell-version.sh — This PR modifies a file under the protected path .github/. The PR carries no linked issue and its Renovate-generated description does not itself explain the rationale beyond restating the version bump, which would ordinarily warrant a high-severity finding for insufficient justification. However, the scope-authorization-implicit finding above cites specific repository configuration (renovate.json's openshell packageRule and its postUpgradeTasks) that explicitly authorizes this exact automated update pattern for this file, so this finding is recorded as informational rather than blocking. Human approval is still required for any change to a protected path, regardless of context.

Previous run

Review

Findings

Info

  • [scope-authorization-implicit] .github/scripts/openshell-version.sh — Authorization inferred from the mechanical nature of this change (a value-only dependency version + SHA pin bump). The automated update pattern is explicitly authorized by renovate.json's custom regex manager tracking OPENSHELL_VERSION in this file, paired with the openshell packageRule's postUpgradeTasks (scripts/renovate/update-openshell-sha.sh) that refreshes OPENSHELL_SHA from the GitHub API after each version bump. The new SHA (4ce767fc0cadad773c398e15109c0286f4b7aa30) matches the commit resolved for tag v0.1.1 in NVIDIA/OpenShell. No architectural review required.

  • [protected-path] .github/scripts/openshell-version.sh — This PR modifies a file under the protected path .github/. The PR carries no linked issue and its Renovate-generated description does not itself explain the rationale beyond restating the version bump, which would ordinarily warrant a high-severity finding for insufficient justification. However, the scope-authorization-implicit finding above cites specific repository configuration (renovate.json's custom manager and openshell packageRule) that explicitly authorizes this exact automated update pattern for this file, so this finding is recorded as informational rather than blocking. Human approval is still required for any change to a protected path, regardless of context.

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 27, 2026
@renovate-fullsend renovate-fullsend Bot changed the title chore(deps): update dependency nvidia/openshell to v0.1.1 chore(deps): update dependency nvidia/openshell to v0.1.2 Sep 28, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:31 PM UTC · Completed 3:43 PM UTC

Commit: eace5eb · View workflow run →

Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $1.76

waynesun09 added a commit that referenced this pull request Sep 29, 2026
OpenShell 0.1.2 is a bug-fix release on top of 0.1.1 with no breaking
changes. It fixes bytes being dropped on proxied connections, the
Homebrew config migration, and reaps orphaned processes as soon as they
exit. Its packaged gateway config is unchanged from 0.1.1.

Bump the pin (and the installer commit), the local-run doc's version
and supervisor image, and the GitLab runner VM fallback versions.
PID 1's arguments changed in 0.1.2, so the stray-process comment no
longer quotes them; the sweep never matched on them.

Verified on macOS arm64 and Fedora 44 x86_64: triage on claude, codex
and pi after upgrading from 0.1.1. On Fedora, the stray-process sweep
killed a planted orphan and spared PID 1 and the keep-alive; on macOS,
the full upgrade from 0.0.116 followed by the same triage runs.

Supersedes #7763.

Assisted-by: Claude
Signed-off-by: Wayne Sun <gsun@redhat.com>
@waynesun09 waynesun09 mentioned this pull request Sep 29, 2026
7 of 8 tasks
@waynesun09

Copy link
Copy Markdown
Member

Superseded by #7233, which now pins OpenShell 0.1.2 (same version and installer commit as this PR). This bump can't merge on its own: main still writes the schema v1 gateway config and ships the _NOOP_* provider credentials, both of which OpenShell 0.1.x rejects. #7233 carries the rest of that migration.

@waynesun09 waynesun09 closed this Sep 29, 2026
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 4:33 PM UTC · Completed 4:39 PM UTC

Commit: eace5eb · View workflow run →

Runtime: claude · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $1.33

@fullsend-ai-retro

Copy link
Copy Markdown

PR #7763 was a Renovate PR bumping NVIDIA/OpenShell 0.0.116 → 0.1.2 via .github/scripts/openshell-version.sh. The review agent (fullsend-ai/agents@main, skills/pr-review) ran twice (as Renovate rebased the PR from v0.1.1 to v0.1.2, ~$3.34 combined cost) and both times scored it 'risk: low (1/5), no architectural review required,' reasoning purely from diff shape: single file, matches a renovate.json packageRule, SHA independently verified against upstream. On 2026-09-29 a human (waynesun09) closed the PR: it can't merge standalone because main still writes a schema-v1 gateway config and ships _NOOP_* provider credentials, both rejected by OpenShell 0.1.x — the real migration is carried by the separate, still-open PR #7233. The bumped dependency's own release notes (present in the PR body) included the exact breaking change ('refactor(config): normalize and enforce gateway schema v2') that would have flagged this, but the review agent never cross-references a dependency's changelog against the target repo's actual usage.

This is not a new class of gap: open issues #3015 (multi-minor/major Renovate bumps should be screened for breaking changes), #3049 (review agent should surface migration/breaking-change warnings already present in dependency PR bodies), and #1778 (review agent should detect breaking API changes in dependency bumps, evidenced by 5 blind approvals before a human caught a break) all describe the same failure mode on other dependencies/repos. #7763 is corroborating evidence for all three — no new proposal filed for this theme to avoid duplicating them. New evidence worth attaching to those issues: the root cause is traceable to explicit 'Early exit criteria' blocks in fullsend-ai/agents at skills/pr-review/sub-agents/intent-coherence.md (lines ~27-32, 34-44, 56-69) and a near-identical block in style-conventions.md, which instruct sub-agents to STOP immediately and not read anything beyond the diff — including not reading the dependency's own release notes for breaking-change language — for anything classified as a 'mechanical, generated, or value-only change (e.g. dependency version bump).' Whoever picks up #3049 (the closest fix, which proposes scanning the PR body for migration/breaking markers) will need to carve an exception into this early-exit rule, since the current instruction actively forbids exactly the investigation #3049 asks for.

Separately, this PR is also a symptom of a repo-specific coordination gap: renovate.json's OpenShell packageRule has no mechanism to pause while the in-flight breaking migration (#7233, open since 2026-09-11) is unresolved, so Renovate kept rebasing the same PR onto newer OpenShell releases, triggering a full paid review-agent run each time on a PR that structurally could never merge. Filed as a new proposal below (repo-specific, not a review-agent gap).

Proposals filed

This branch was successfully deployed

1 active deployment
dev — eace5eb5 Deployed Sep 28, 2026 by renovate-fullsend[bot] via behaviour #14303
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

requires-manual-review Review requires human judgment risk/low PR risk: low

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant