fix(eval): update new campaign dependencies without rewriting frozen evidence - #244
Merged
Merged
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.14.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.14.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The original PyJWT bump changed a frozen benchmark requirements file without changing the environment that produced the retained results. Following the runbook would install 2.15.0 while the campaign validator required the observed 2.14.0, stopping execution with
frozen dependency mismatch: pyjwt.Preserve the historical requirements and inventory unchanged. New campaigns use a separate requirements file with PyJWT 2.15.1 and capture their actual installed distributions into a new private inventory before preparing a manifest. Inventory capture refuses to overwrite existing files. Dependabot excludes only the historical requirements file; new campaign dependencies remain eligible for updates. Retained continuation commands keep their original inventory.
Validation: Ruff, 87 offline benchmark campaign/locking/preflight tests, all 114 historical pins matched against the retained inventory, documented PowerShell capture exercised against installed metadata, overwrite rejection verified, and an independent review found no blockers. This update makes no claim that a new benchmark campaign or complete installation of the successor requirements was run.