Skip to content

chore(ci): bump Quantum-L9/l9-ci-core/.github/actions/provision-sdk from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1 - #213

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/Quantum-L9/l9-ci-core/dot-github/actions/provision-sdk-0d28395428426853c44825c4645c23ee8ace23b1
Closed

chore(ci): bump Quantum-L9/l9-ci-core/.github/actions/provision-sdk from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1#213
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/Quantum-L9/l9-ci-core/dot-github/actions/provision-sdk-0d28395428426853c44825c4645c23ee8ace23b1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps Quantum-L9/l9-ci-core/.github/actions/provision-sdk from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1.

Commits
  • 0d28395 Claude/pr remediation skill pfqo8f (#94)
  • de469af feat(typescript-preset): stamp locked Biome contract instead of inventing bio...
  • cd793fc docs: footnote live @​v1 tip in AGENTS.md
  • 7fa8b63 ci(self): beef up Core PR CI with lint, analysis dogfood, and security
  • 373bb6d ci: bump actions/setup-python from 5.6.0 to 7.0.0 (#87)
  • 728fd86 ci: bump ossf/scorecard-action (#86)
  • 12eb8d3 deps(uv): bump pytest from 8.4.2 to 9.1.1 (#85)
  • ade33c3 deps(consumer-ci): bump pytest from 8.4.2 to 9.1.1 (#84)
  • 8bfaffe deps(consumer-ci): bump mypy from 1.19.0 to 2.3.0 (#82)
  • 5cb18b2 deps(consumer-ci): bump the consumer-ci-minor-patch group with 3 updates (#81)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [Quantum-L9/l9-ci-core/.github/actions/provision-sdk](https://github.com/quantum-l9/l9-ci-core) from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1.
- [Commits](Quantum-L9/l9-ci-core@f881165...0d28395)

---
updated-dependencies:
- dependency-name: Quantum-L9/l9-ci-core/.github/actions/provision-sdk
  dependency-version: 0d28395428426853c44825c4645c23ee8ace23b1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automerge-candidate, dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from cryptoxdog as a code owner August 17, 2026 18:23
@github-actions

Copy link
Copy Markdown

PR reviewable size is within recommended limits

@github-actions

Copy link
Copy Markdown

L9 Audit Harness Report

  • Generated: 2026-08-17T18:23:33.984858+00:00
  • Repo root: /home/runner/work/Cognitive.Engine.Graphs/Cognitive.Engine.Graphs
  • Overall result: ✅ PASSED
  • Exit code: 0

Step Results

Step Status Exit Code Notes
Architecture Audit ✅ Passed 0
Spec Coverage ✅ Passed 0
Contract Wiring ✅ Passed 0

Architecture Audit Findings

Severity Count
🔴 CRITICAL 0
🟠 HIGH 0
🟡 MEDIUM 25
🔵 LOW 0

See artifacts/audit_report.md for full details.

Spec Coverage

  • ✅ Implemented: 37
  • ⚠️ Partial: 9
  • ❌ Missing: 0
  • Total features: 46
Category Implemented Partial Missing Total
gates 10 0 0 10
scoring 7 0 0 7
v1.1_node 2 0 0 2
v1.1_edge 2 0 0 2
v1.1_action 0 2 0 2
v1.1_scoring 1 1 0 2
action_handler 0 6 0 6
gds_algorithm 5 0 0 5
research_pattern 10 0 0 10

See artifacts/coverage_report.md for full details.

Next Steps

All checks passed. Safe to merge.

@cryptoxdog

Copy link
Copy Markdown
Collaborator

Closing Dependabot PR as part of Quantum-L9 org-wide cleanup. Human/agent PRs remain open.

@cryptoxdog cryptoxdog closed this Aug 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/Quantum-L9/l9-ci-core/dot-github/actions/provision-sdk-0d28395428426853c44825c4645c23ee8ace23b1 branch August 21, 2026 13:08
@cryptoxdog

Copy link
Copy Markdown
Collaborator

Replaced by the stacked PRs (this sibling is already closed):

Merge those bottom-up: 217 → 218 → 219. Do not squash 217 or 218 while a child is open.

cryptoxdog added a commit that referenced this pull request Aug 21, 2026
* chore(ci): collapse Dependabot pin refresh into one stack base

Replace the overlapping #212/#213/#215/#216 siblings with a single
bottom-of-stack commit: l9-ci-core pins to 0d28395, upload-artifact
v7.0.1, and SPDX AND expressions on the license allow-list fallback
so the observability layer can pass Dependency Review.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(deps): bump observability group on the pin-refresh base

structlog 26.1.0 and prometheus-client 0.26.0 from #211. Lands on
chore/stack-ci-pins so the SPDX AND allow-list is already present.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(ci): bump attest-build-provenance to v4.2.2

Independent docker-build.yml change from #214, stacked on the
observability layer so the three PRs merge oldest-first without
file fights.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): use compatible sdk-revision and keep SPDX AND licenses

Baseline ratchet at l9-ci-core@0d28395 only lists b1a49141. Repo
ALLOWED_LICENSES would drop Dual-license compounds from a fallback.
Widen Docker/pip structlog to match Poetry 26.1.0.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): allow Dual-license observability via purl, hash-pin artifacts

SPDX AND strings in allow-licenses did not match package Dual licenses
and broke MIT matching for upload-artifact. Allow structlog and
prometheus-client by purl; pin upload-artifact to v7.0.1 by hash.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant