Repository navigation
Dependency Dashboard #8
Description
Activity
Action required: Issue inactive for 30 days.
Status update or closure in 7 days.
Action required: Issue inactive for 30 days.
Status update or closure in 7 days.
Action required: Issue inactive for 30 days.
Status update or closure in 7 days.
Issue closed after 7 days of inactivity.
Dependency Dashboard #8 — finite review, 2026-09-16
Source: #8
Board: ab0c3981-5c8f-4a07-be71-7e032ba5baf1 / 1b6f2cd0-9d57-41d5-be3f-5c19893e2d91
Scope and disposition
Frozen inventory: 2026-09-16 04:54 UTC, all 15 open bot dependency PRs. All 31 open PRs and paginated closed PR history were retrieved; no duplicate implementation PR is needed. Main inspected: 6ed5d37. This is a finite REVIEW of existing updates, not permanent completion of recurring maintenance. Dashboard remains open. Board disposition: Blocked / Needs Input; none promoted to PR Ready.
No merges, approvals, closures, workflow approvals, bot rebase/reset commands, source changes, commits, pushes, installations or builds. No other board issue started; #3860 remains the other active work. Source worktree not needed/created; future authorized source work belongs in /home/forge/worktrees/dependencies. No other worker artifacts touched. Initial disk availability was about 1.1 GiB, not enough for safe dependency builds.
Complete inventory and latest-head findings
B = Build and Test; P = Performance: zsh rprompt; L = Lint Fix. These are existing remote results, NOT locally rerun tests. All fifteen have successful Release Drafter, which is not readiness evidence. Skipped release builds are not passes. No ACTION_REQUIRED checks/runs found in fetched head checks, actions runs, or PR status rollups. Actual CI failures need fixing, not workflow-execution approval.
| PR | Head | Actual update / classification | Remote B/P/L | Evidence / next action |
|---|---|---|---|---|
| #3537 | b4e548d | checkout v6→v7; automation major, overlaps #3873 | fail/pass/fail | 5 generated-workflow tests fail OutdatedWorkflow; nightly double_must_use errors. Update Rust generator and YAML together only with authorization. Checkout v7 changes unsafe fork checkout behavior for pull_request_target/workflow_run; do not bypass its safeguard. |
| #3558 | 36c27bb | handlebars 6.4.1→6.4.4; isolated patch | pass/pass/fail | String-safety job fails double_must_use in forge_domain. Existing approval refers to older 08903af, not latest head. Validate template ordering/partials; release notes reverse default preserve_json_order in 6.4.4. Upstream benchmark quick-xml removal alone does not establish a Forge production vulnerability. |
| #3629 | 24f5997 | cmov 0.5.3→0.5.4; lowest-risk patch candidate | pass/pass/pass | BEHIND main, July CI, automatic rebases disabled after 30 days. Diff is version/checksum only; head lockfile reflects older base, so do not replace current main lockfile wholesale. Needs refreshed integration tests/lints and relevant CLI validation before readiness. |
| #3694 | fafdd6d | serde_with/macros 3.18→3.21 (+bs58); SECURITY priority | pass/pass/fail | GHSA-7gcf-g7xr-8hxj medium, affected >=2.3,<3.21; current main 3.18. String-safety double_must_use blocks. Google cloud RPC/WKT transitively consume it; exploitable call-path reachability not proven. |
| #3744 | 08b8027 | gh-workflow 0.8.1→0.9; pre-1.0 breaking migration | fail/fail/fail | E0063: PullRequestTarget lacks paths/paths_ignore in release_drafter.rs. Also present in #3874; not safe to assume grouped PR fixes it. Requires generator compatibility fix and generated-workflow tests, with automation-change permission. |
| #3762 | cd101e1 | quinn-proto 0.11.14→0.11.16 (+rand_pcg); SECURITY priority | pass/pass/fail | GHSA-4w2j-m93h-cj5j high, unbounded out-of-order reassembly memory exhaustion, patched >=0.11.15. Main 0.11.14 is affected by version. String-safety double_must_use blocks. reqwest→quinn→quinn-proto lock graph; runtime HTTP/3 feature/reachability not established. |
| #3775 | 8433284 | stale v10→v11; automation major, overlaps #3873 | fail/pass/fail | Generated stale workflow OutdatedWorkflow; double_must_use lint. Upstream notes ESM migration and brace-expansion security fixes; review runner/runtime and preserve stale/closure policy. Do not execute stale workflow as a test. |
| #3778 | 2a8ce30 | rmcp manifest v3, lock 3.4.0; breaking migration | fail/fail/fail | RawContent removed, ContentBlock.raw removed, start_authorization now one config argument; ClientInfo deprecated in 3.4 (warnings denied). Needs content conversion and OAuth registration/login migration, credential and stdio/HTTP MCP tests. Current 3.4 lock is NEWER than #3874's 3.3; group does not supersede this. |
| #3831 | 6a09575 | posthog manifest 0.25.0, lock 0.25.2; pre-1.0 migration candidate | pass/pass/pass | 4 files include extra fd.rs bool simplification and transitive lock re-resolution. Renovate PR Edited/Blocked, with two autofix commits. No human review. #3874 has newer 0.25.4 but fails and is not a validated replacement. Verify telemetry opt-out, flush/shutdown and error propagation. |
| #3835 | e6c74dc | google-vertex lock 5.0.46→5.0.63; JS patch candidate | pass/pass/pass | 2 files: package-lock plus same unrelated fd.rs simplification. PR Edited/Blocked; dashboard advertises 5.0.84 but actual head is .63. Node >=22 and provider/provider-utils transitive changes. Rust CI does not establish TS evaluation compatibility or Vertex authentication. |
| #3836 | 9c0cf79 | ai lock 7.0.57→7.0.79; JS patch candidate | pass/pass/pass | 2 files: package-lock plus fd.rs simplification. PR Edited/Blocked; dashboard advertises 7.0.102 but actual head is .79. Overlaps #3835's provider-utils graph, not a duplicate top-level update. Need Node >=22 install/typecheck and semantic-search evaluation smoke tests. |
| #3837 | abda691 | async-trait 0.1.91→0.1.92; isolated patch | pass/pass/fail | Unlike other old macro failures, remaining double_must_use is async_recursion in forge_services/policy.rs. Do not assume async-trait alone fixes lint baseline. |
| #3838 | dcfcc3f | thiserror/impl 2.0.19→2.0.20; isolated patch | pass/pass/fail | String-safety double_must_use in forge_domain. 1.x copy is unchanged; validate derives and error handling on refreshed base. |
| #3873 | 1287aee | checkout 7 + stale 11 + setup-rust-toolchain 2 + autofix action SHA; grouped automation | fail/pass/fail | 6 generated-workflow tests fail OutdatedWorkflow. Clippy warnings denied under toolchain v2; inspect warning policy migration, do not weaken gates. Contains #3537/#3775 version changes but also two extra automation changes. Choose group vs individual route; no closures performed. |
| #3874 | 556f407 | 10 Rust major/pre-1.0 updates; defer broad group | fail/fail/fail | rmcp API compile failures confirmed. Includes gh-workflow 0.9 and posthog 0.25.4 overlap plus convert_case 0.12, dirs 7, sysinfo 0.39.6, termimad 0.35.4, nucleo-picker 0.12.2, async-openai 0.42, gix 0.87.1. No code migrations. Broad lock churn; later compiler errors may be masked. |
Duplicate / supersession decisions
- chore(deps): bump the actions group across 1 directory with 4 updates #3873 contains the action changes in chore(deps): update actions/checkout action to v7 #3537 and chore(deps): update actions/stale action to v11 #3775, but is not a safe replacement until generator and toolchain-policy migrations are verified. Prefer small individual updates unless maintainer explicitly selects the group. No bot configuration edits or bulk closes.
- build(deps): Bump the major group across 1 directory with 10 updates #3874 overlaps chore(deps): update rust crate gh-workflow to 0.9.0 #3744/chore(deps): update rust crate rmcp to v3 - autoclosed #3778/fix(deps): update rust crate posthog-rs to 0.25.0 #3831. It has newer PostHog but older rmcp than the individual head; there is no single superseding group. Prefer existing individual migrations sequentially. The seven other upgrades in the group must not be silently treated as verified.
- chore(deps): update dependency @ai-sdk/google-vertex to v5.0.63 #3835/chore(deps): update dependency ai to v7.0.79 #3836 share lockfile and provider dependencies; neither replaces the other. Their two autofix commits explain Renovate Edited/Blocked. Reset/rebase checkboxes discard commits: require maintainer decision rather than clicking them.
- fix(deps): update rust crate posthog-rs to 0.25.0 #3831's fd.rs simplification is also in chore(deps): update dependency @ai-sdk/google-vertex to v5.0.63 #3835/chore(deps): update dependency ai to v7.0.79 #3836. It appears behavior-preserving, but is outside each dependency's purpose; record scope acceptance or remove only through authorized contributor coordination.
- Closed rmcp v2 chore(deps): update rust crate rmcp to v2 - autoclosed #3595 was autoclosed, not merged; v1.8 chore(deps): update rust crate rmcp to v1.8.0 #3554 merged. Closed sysinfo chore(deps): update rust crate sysinfo to 0.39.0 #3293 and termimad chore(deps): update rust crate termimad to 0.35.0 #3665 are blocked in the dashboard; build(deps): Bump the major group across 1 directory with 10 updates #3874 reintroduces those upgrades as part of its group. Rate-limited updates and deprecated @types/handlebars are outside this frozen pass.
Exact validation and gaps
Performed (read-only network/API plus local parsing):
gh api repos/tailcallhq/forgecode/issues/8;gh api --paginate 'repos/tailcallhq/forgecode/issues/8/comments?per_page=100'; same for timeline. Dashboard body differs from actual edited PR versions; actual heads take precedence.gh api --paginate 'repos/tailcallhq/forgecode/pulls?state=open&per_page=100'andstate=closed; all pages persisted. This gh lacks--slurp; initial rejected calls were retried usingjq -s addor JSONDecoder page folding.- For EACH scoped N: GET pulls/N; paginated files, reviews, review comments, commits and issues/N/comments; full diff via
gh api -H 'Accept: application/vnd.github.diff' repos/tailcallhq/forgecode/pulls/N. Captured head SHA identifies the reviewed version. No latest-head human approval found: the only approval, chore(deps): update rust crate handlebars to v6.4.4 #3558, targets an older commit. - For EACH head SHA: paginated commits/SHA/check-runs, commits/SHA/status, actions/runs?head_sha=SHA;
gh pr view N --repo tailcallhq/forgecode --json number,state,headRefOid,mergeStateStatus,reviewDecision,statusCheckRollup. All 15 inspected; no ACTION_REQUIRED. Query jobs for latest ci and autofix.ci run on each head.gh run view ID --log-failedreturned empty output despite exit 0; this is NOT passing evidence. Retrieved actual failed job logs withgh api repos/tailcallhq/forgecode/actions/jobs/ID/logsinstead. gh api repos/tailcallhq/forgecode/commits/mainand SHA-pinned raw main/head contents. Pythontomllib.loadsparsed every changed Cargo.lock/Cargo.toml and tracker manifest;json.loadsparsed both changed package-lock files. All parsed. Version-set deltas are in static-validation.txt. Parsing is not Cargo resolution or compatibility testing. The build(deps): bump cmov from 0.5.3 to 0.5.4 #3629 current-main comparison includes base-age differences, NOT additional changes in its PR diff.gh api advisories/GHSA-7gcf-g7xr-8hxj; paginatedgh api 'advisories?ecosystem=rust&affects=quinn-proto&per_page=100'. Verified patched version ranges; not a full cargo audit or exploitability assessment. Earlier Quinn panic advisory GHSA-6xvm-j4wr-6v98 was already fixed by current 0.11.14.- Read AGENTS.md and debug-cli skill. Semantic search unavailable (revoked/replaced Forge token); literal search used successfully. GitHub API access works, no GitHub login required for this review.
NOT RUN: cargo check/test/insta/clippy/build; npm ci/typecheck/tests; debug-cli --help/-p against any PR build; provider-authenticated Vertex or MCP OAuth flows; platform-specific tests. No relevant PR binary was built. Disk constraint and no authorization to alter automation prevent safe implementation/verification now. No tests deleted or snapshots accepted. Green existing CI on #3629/#3831/#3835/#3836 is useful but insufficient for project PR Ready acceptance.
For future authorized work, one PR at a time: isolated durable worktree; budget disk before compilation; crate-specific tests and lints; debug build then --help before relevant noninteractive -p smoke checks; preserve conversation originals. For #3744/#3537/#3775/#3873, ask whether to correct implementation/generator (recommended), not update failing tests to suppress drift. For #3778, test content handling, OAuth flows and token storage on its exact chosen version. #3874 additionally needs paths/home-dir platform behavior, sysinfo startup regression, terminal rendering/picker behavior, async-openai DTO and gix compatibility checks.
Needed decisions / recommended order
- Prioritize existing build(deps): Bump quinn-proto from 0.11.14 to 0.11.16 #3762 then build(deps): Bump serde_with from 3.18.0 to 3.21.0 #3694 security updates; refresh/retest sequentially on current main once adequate disk or a suitable runner is provided. Do not fix unrelated macro lint failures independently in every PR; establish whether they persist on rebased main first.
- Select individual PR route versus grouped chore(deps): bump the actions group across 1 directory with 4 updates #3873/build(deps): Bump the major group across 1 directory with 10 updates #3874. Recommend individual migrations; do not close groups or change bot automation without explicit direction.
- Authorize narrowly scoped workflow-generator/automation migration work if desired, including the toolchain v2 warnings-policy review. No workflow execution approval has been requested by these 15 heads at this inventory.
- Accept or remove the small unrelated fd.rs autofix delta in the three edited candidates; choose whether to keep current frozen versions or permit a bot refresh. Never silently discard bot/manual commits.
- Provide disk capacity/build runner for exact-head verification. Vertex credentials are needed only for live evaluation smoke tests; do not disclose tokens in evidence. No fresh duplicate PR should be created for these existing updates.
Evidence layout: inventory.json, inventory-time.txt, dashboard*.json, open-prs.json, closed-prs.json, main*.json/toml/lock/yml, security advisory JSON, static-validation.txt; each PR directory contains pr/files/reviews/comments/commits/checks/status/runs/rollup JSON, full diff.patch, jobs JSON, failed job logs and ANSI-stripped clean.txt, and parsed head manifests/lockfiles.
Co-Authored-By: ForgeCode noreply@forgecode.dev
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Repository Problems
These problems occurred while renovating this repository. View logs.
Deprecations / Replacements
Warning
The following dependencies are either deprecated or have replacements available.
Other Branches
The following updates are pending. To force the creation of a PR, click on a checkbox below.
Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
Detected Dependencies
cargo (26)
devcontainer (1)
github-actions (7)
npm (1)
rust-toolchain (1)