Skip to content

fix(deps): adopt reviewed cloud-commitments-go purchase safeguards #2121

Description

@cristim

Confirmed release gap

Main go.mod still requires all four cloud-commitments-go modules (pkg, providers/aws, providers/azure, providers/gcp) at v0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. This predates the merged GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.

The coordinated old pins compile, so this is not a claim that the CLI currently has the standalone provider compile error. Updating the library repository alone does not deliver its newer behavior to this CLI.

References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144. #144 explains why recent GCP commitments failed to suppress later recommendations before the library fix.

Scope

Update the four library requirements and corresponding sums together to published merged commit a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve each canonical module version and confirm source hashes. Do not use local replacements, vendor copies, branch-only unpublished revisions, unrelated upgrades or release automation. Add only consumer regressions necessary to verify the adopted behavior; this issue does not authorize cloud purchases or deployment.

Acceptance

  • With the repository CI-pinned toolchain and GOWORK=off, capture all four selected library module versions with no replacements. Require tidy-diff, vet and pinned lint to pass.
  • Build the actual CLI using make build or go build -o <temporary-output> ./cmd; run the command package race/short suite.
  • Exercise recommendation-to-purchase filtering through the CLI's actual entry path with fake cloud boundaries: a recent matching GCP CUD suppresses the retry, recent unknown AWS reservation states remain owned, and Redis/Valkey or missing ElastiCache engine matching uses the updated policy. Preserve explicit-zero versus absent purchase cost through output and fail-closed interruption/retry behavior.
  • Show an applicable new regression fails with the old pins and passes with the new pins. Do not invoke real purchases or --yes.
  • Record the reviewed commit, checks and artifact/release status without claiming deployment from a merged dependency change.

Triage

P2 / medium / this-sprint / few / small: older dependency pins are confirmed, but no live incident or consumer-specific failing purchase path has been reproduced in this tracking task. The upstream P1 financial-risk fix warrants timely adoption; its label is not automatically evidence for a consumer P1. Reassess severity/priority if end-to-end reproduction confirms repeat-purchase exposure.

Activity

  1. cristim commented on Oct 7, 2026

    @cristim
    MemberAuthor

    claimed by cc-cli-w2

  2. cristim commented on Oct 7, 2026

    @cristim
    MemberAuthor

    Rollout-relay note from cc-cli (worker 1): per the orchestrator's relay for cloud-commitments-go PR #218 (fix(azure): stop dividing the monthly run-rate by the term months, merged as e24345c), I am cutting a narrow deps PR that bumps ONLY providers/azure to e24345c (plus the pkg pin the azure module requires). aws/gcp pins untouched. When you implement this issue (#2121), either build on that branch or exclude the azure pin to avoid a go.mod conflict.

  3. cristim commented on Oct 8, 2026

    @cristim
    MemberAuthor

    Fixed by #2141, merged as bef177f. The CLI now pins cloud-commitments-go providers/aws and providers/gcp at 7ff8c1aee1bb (pkg 90e61e668b99 and Azure 58c25f04c49b were already newer on main and contain the reviewed a32fd1a178e9 safeguards). Consumer regression tests cover the GCP commitment-family dedupe (fails on the previous GCP pin), Redis/Valkey matching, reservation ownership, explicit-zero vs absent purchase cost, and fail-closed interruption through the CLI's own purchase paths. Post-merge CI on main is being watched.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions