Skip to content

chore(deps): bump actions/setup-python from 5 to 6 - #3

Merged
ManSio merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-python-6
Jul 18, 2026
Merged

ManSio merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-python-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/setup-python from 5 to 6.

Release notes

Sourced from actions/setup-python's releases.

v6.0.0

What's Changed

Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Enhancements:

Bug fixes:

Dependency updates:

New Contributors

Full Changelog: actions/setup-python@v5...v6.0.0

v5.6.0

What's Changed

Full Changelog: actions/setup-python@v5...v5.6.0

v5.5.0

What's Changed

Enhancements:

Bug fixes:

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

ManSio pushed a commit that referenced this pull request Jul 18, 2026
Security (#1-#3, #14):
- ExecuteScriptTool: feature flag MSCODEBASE_EXECUTE_SCRIPT_ENABLED=false,
  clean PATH, честный докстринг (убрано 'E2B-песочница')
- HeartbeatService._shutdown: os._exit(0) -> sys.exit(0) + _shutdown_services()
- .env.example: документирован флаг

Static analysis (#8):
- F821 убран из ruff.toml ignore
- 5 скрытых NameError починены (_ext_root, numpy, typing Any)
- Per-file-ignores для 4 legacy-файлов

Декомпозиция Indexer (Фаза 6):
- IndexParser: чистый парсер без DB/SymbolIndex (175 строк)
- Indexer._parse_file_only: 143 -> 70 строк
- IndexPipeline: -138 строк, использует IndexParser
- AST-кэш: двойной парсинг устранён
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-python-6 branch from 780a1e6 to e2523ff Compare July 18, 2026 04:36
@ManSio
ManSio merged commit c8f7402 into main Jul 18, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/setup-python-6 branch July 18, 2026 10:09
ManSio pushed a commit that referenced this pull request Jul 22, 2026
…ment

Fixed issues (all verified against actual source code):
- #3: avg_results rolling average formula used '-' instead of '+'
- #4: sync_wrapper run_until_complete in running loop → _SYNC_POOL.submit()
- #5: MD5 vs SHA256 hash mismatch causing eternal dirty files
- #7: split(';') Windows-only → os.pathsep for cross-platform
- #10: Contradiction Ledger started twice (main + server_factory)
- #11: Dead code _trigger_auto_index_if_empty (70 lines removed)
- #13: Unassigned expression in get_global_idle_metrics
- #14: _cleanup_old_progress never called → periodic cleanup added
- #15: gc.collect() after every file → every 50 files
- #25: log_crash ignored error parameter → traceback.print_exception
- #26: Import immediately overwritten → removed unused imports

Refuted (false positives):
- #1: Factory correctly called with (self) at L138
- #2: err or '' correct at L361
- #8: asyncio.Lock lazy binding OK in Python ≥3.10
- #12: _format_success_response deep-copies via _sanitize()

Tests: 185 passed, 0 regressions (35 pre-existing failures unchanged)
ManSio pushed a commit that referenced this pull request Aug 4, 2026
Third external audit: SQL x6, '14 subprocess without timeout', dead code
(_BATCH_SIZE, ONNX_*, adapters), experiments-in-prod. Verified: SQL — same
refuted parameterized IN-pattern; graph.py subprocess calls both have
timeout=60; dead code already removed (_BATCH_SIZE on 08-03, ARCHITECTURE.md
marks ONNX_* deleted, adapters don't exist); metrics (251 async/626 except/
24 sleep/27 global) exact; ruff 88-file BLE001 is declared gradual cleanup.
Report: docs/ISSUES/review_full_2026-08-04.md. Tests: 761 passed.
ManSio pushed a commit that referenced this pull request Sep 26, 2026
22 runs (2 conditions x 3 models x runs), variant pinned high, all rc=0.
Validator clean 13/22; arrival 10/11, symptom 3/11.

Key finding: the arrival-index condition generalizes (must-hit 33/33,
must-NONE 32/33). The symptom-index drop is isolated to item #3, a
morphological twin of the catalogue's own arrival sentence
('timing out / retry' vs 'times out / try') -> trivially matched under
arrival, not under the symptom key. G6 token-overlap gate cannot see it
(table rows are not numbered; morphology not normalized) - OPEN for F6.

- scripts/f4b_aggregate.py: reproducible per-item/per-condition summary
- results/f4b/RESULTS.md + manifest.json + raw outputs
- runner now stores handout as a repo-relative path (F0 privacy class)
ManSio pushed a commit that referenced this pull request Sep 26, 2026
Six attacks, none FATAL. Verdict: arrival-index generalization
DEFENDED (10/11, must-hit 33/33); symptom-index claim OPEN/lowered
to 'direction' - the drop is one contaminated item (#3, a
morphological twin of the catalogue arrival sentence) plus no
closed-book arm and control-only validation.
ManSio pushed a commit that referenced this pull request Sep 26, 2026
AGENT_DIARY: F4b numbers + root cause for item #3.
KNOWN_ISSUES: G6 novelty gate is blind to table-row and
morphological twins of index phrases (Open).
ManSio pushed a commit that referenced this pull request Sep 26, 2026
F4b exposed that frozen_overlap_check.py v1 was blind to probes
that paraphrase a catalogue arrival phrase (item #3: 'timing out /
retry' vs 'times out / try'): it only saw numbered lines and did no
morphology. v2 compares numbered probes of previous lists AND the
catalogue arrival register, with light stemming; item #3 is now
flagged with zero false positives.

Controls: --selftest (negative twin flagged + positive clean) and
tests/test_frozen_overlap_check.py pin the behaviour. Docs, diary and
KNOWN_ISSUES updated (G6 gap -> Fixed).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant