build(deps): bump uv from 0.12.3 to 0.12.5 in the python group - #52
Merged
Merged
Conversation
Bumps the python group with 1 update: [uv](https://github.com/astral-sh/uv). Updates `uv` from 0.12.3 to 0.12.5 - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.3...0.12.5) --- updated-dependencies: - dependency-name: uv dependency-version: 0.12.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python ... Signed-off-by: dependabot[bot] <support@github.com>
gabrielspadon
enabled auto-merge (squash)
September 1, 2026 12:04
gabrielspadon
added a commit
that referenced
this pull request
Sep 5, 2026
## What broke `RefreshEngine.run` compares the bound discovery policy epoch against its own wall clock (`citeforge/refresh/engine.py:116`), and derives the inventory task epoch from that same clock (`engine.py:142`). `Ledger.commit_initial_round` then requires the inventory authority to agree with the bound discovery policy (`citeforge/refresh/ledger.py:4463`). Four tests in `tests/test_refresh_discovery.py` wrote the literal month they were authored in (`"2026-08"`), so they agreed with the engine for exactly one calendar month. When the clock rolled to `2026-09` the engine started deriving `2026-09` while the bound policy still said `2026-08`, and all four began raising: ``` ValueError: inventory authority conflicts with bound discovery policy ``` That is a test-only defect. No production code path pins a month, and the monthly workflow derives its own with `date +%Y-%m`. ## Blast radius Every `Test (py3.10 … py3.14)` leg failed identically, which failed the `Required CI` aggregate and left PR #52 (a Dependabot `uv` bump touching only `requirements-build.in` and `.lock`) `BLOCKED` on a failure it did not cause. Any PR opened after 2026-09-01 would have been blocked the same way. ## Fix Both engine-driving test modules derive the epoch exactly as the engine does. The staleness test builds its rejected month as an explicit offset from today rather than naming one. Two guard tests were also passing on the right status for the wrong reason. `test_generation_start_binds_discovery_preflight_before_inventory_send` was tripping the epoch mismatch instead of the missing `s2` credential it exists to prove. Both it and the staleness test now pin the exact `detail` string their guard must return, so a guard that starts firing for a different cause fails instead of passing silently. `test_no_refresh_test_pins_a_literal_freshness_epoch` fails on any double-quoted `YYYY-MM` literal in a `test_refresh_*.py` module that drives `RefreshEngine`, so this cannot be reintroduced. Single-quoted months inside the SQL of `test_refresh_corpus.py` write a deliberately mismatching epoch to trip a drift guard and are correctly left alone. ## Verification Run locally on Python 3.14.7 against `origin/main`. - Reproduced first: the same 4 failures, same `ValueError`, before any edit. - `pytest -m 'not live'` (CI's exact invocation): **2077 passed, 2 skipped, 7 deselected**. - `ruff check citeforge/ tests/ main.py`: clean. - `mypy citeforge/ main.py`: clean, 56 source files. - The four previously-detonating tests re-run under a simulated `2027-02` clock: all pass, confirming the time coupling is gone rather than merely re-pinned to the current month. - The new guard was proved to fail by reintroducing a literal into `test_refresh_discovery.py`, then restored. Merging this unblocks #52.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python group with 1 update: uv.
Updates
uvfrom 0.12.3 to 0.12.5Release notes
Sourced from uv's releases.
... (truncated)
Changelog
Sourced from uv's changelog.
... (truncated)
Commits
210d1f6Bump version to 0.12.5 (#21140)802a916Sync latest Python releases: 3.10.21, 3.11.16, 3.12.14 (#21138)a6904bbOrder equal-priority Python installations by key (#21134)728a70dImprove automated fixes for related bug manifestations (#21102)b82b038Include hashes in cyclonedx exports (#21131)8011778Simplify editable requirement errors and hints (#21130)dca33f5Fall back to logical cache accounting on unsupported filesystems (#21133)3a76e49Get rid ofLock::with_manifest, makeLock::from_resolutiontake the manif...7e6caa4Support referencing indexes by name via--indexand--default-index(#17455)298dda4Fix relative indexes in PEP 723 scripts (#21097)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions