chore(deps-dev): bump @stdy/cli from 0.22.1 to 0.22.2 - #3719
Conversation
Castiron custom code✅ No new custom-code files detected. 34 mixed files remain; 0 existing customizations changed. Compared 34 existing customizations unchanged
A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 33119705747 --repo openai/openai-python \
--name castiron-custom-code-33119705747-1 --dir /tmp/castiron-custom-code-33119705747-1
git apply --stat /tmp/castiron-custom-code-33119705747-1/custom-code.patch
cat /tmp/castiron-custom-code-33119705747-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin f6276194cda9b95499d3ebc3d6d013e730bf0490 d5d32ef5e0bae42e56f43830dfa9bb5b86808c20
python3 scripts/castiron/custom_code_report.py report \
--base f6276194cda9b95499d3ebc3d6d013e730bf0490 \
--head d5d32ef5e0bae42e56f43830dfa9bb5b86808c20 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-d5d32ef5e0ba
cat /tmp/castiron-custom-code-d5d32ef5e0ba/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
HAYDEN-OAI
left a comment
There was a problem hiding this comment.
Reviewed 85db7d104a60cca40b34be5852d73b5e52d0571a across all three changed files and the local launcher/bootstrap context. The CLI and all five optional platform packages are consistently pinned to 0.22.2, and the fixture now takes its expected installed version from the copied manifest without weakening the local-only launcher checks. The upstream release diff contains license/version updates rather than functional CLI changes. No actionable findings.
Validation: static source, lockfile, test, and upstream release review. I did not install or execute dependencies, run tests, or independently verify the published tarball hashes.
Bumps [@stdy/cli](https://github.com/dgellow/steady) from 0.22.1 to 0.22.2. - [Release notes](https://github.com/dgellow/steady/releases) - [Changelog](https://github.com/dgellow/steady/blob/main/CHANGELOG.md) - [Commits](dgellow/steady@v0.22.1...v0.22.2) --- updated-dependencies: - dependency-name: "@stdy/cli" dependency-version: 0.22.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
85db7d1 to
d5d32ef
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Approved after verifying the dev-only Steady 0.22.2 patch, upstream MIT-only release change, integrity-pinned optional platform binaries, unchanged supply-chain protections, manifest-derived regression fixture, and green Python/HTTPX2/build/security/Castiron required checks on commit d5d32ef.
Bumps @stdy/cli from 0.22.1 to 0.22.2.
Release notes
Sourced from @stdy/cli's releases.
Changelog
Sourced from @stdy/cli's changelog.
Commits
983ba87chore: release v0.22.27c0c5c4chore: change license to MITDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)