Skip to content

chore(deps): update go-openapi packages to v1 - #310

Open
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/major-go-openapi
Open

red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/major-go-openapi

Conversation

@red-hat-konflux-kflux-prd-rh03

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot commented Jul 13, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
github.com/go-openapi/jsonpointer v0.24.0v1.0.1 age confidence
github.com/go-openapi/jsonreference v0.21.6v1.0.2 age confidence

Release Notes

go-openapi/jsonpointer (github.com/go-openapi/jsonpointer)

v1.0.1

Compare Source

1.0.1 - 2026-09-04

Full Changelog: go-openapi/jsonpointer@v1.0.0...v1.0.1

14 commits in this release.


Documentation
Miscellaneous tasks
Updates

People who contributed to this release

jsonpointer license terms

License

v1.0.0

Compare Source

1.0.0 - 2026-07-07

Stable API pledge - no change from v0.24.0

Full Changelog: go-openapi/jsonpointer@v0.24.0...v1.0.0

2 commits in this release.


Documentation

People who contributed to this release

jsonpointer license terms

License

go-openapi/jsonreference (github.com/go-openapi/jsonreference)

v1.0.2

Compare Source

1.0.2 - 2026-09-04

Full Changelog: go-openapi/jsonreference@v1.0.1...v1.0.2

4 commits in this release.


Refactor
Documentation
Updates

People who contributed to this release

jsonreference license terms

License

v1.0.1

Compare Source

1.0.1 - 2026-08-25

Full Changelog: go-openapi/jsonreference@v1.0.0...v1.0.1

12 commits in this release.


Fixed bugs
  • fix: keep NormalizeURL's output parseable when dropping a default port by @​fredbi ...
Documentation
Performance
  • perf: replace the duplicate-slash regexp in NormalizeURL with a scan by @​fredbi ...
Miscellaneous tasks
Updates
Other (technical)

People who contributed to this release

jsonreference license terms

License

v1.0.0

Compare Source

1.0.0 - 2026-07-07

Stable API pledge - no change from v0.21.6

Full Changelog: go-openapi/jsonreference@v0.21.6...v1.0.0

10 commits in this release.


Documentation
Miscellaneous tasks
Updates

People who contributed to this release

jsonreference license terms

License


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 02:00 AM and 04:59 AM, Monday through Friday (* 2-4 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot added area/dependency Issues or PRs related to dependency changes major-update manual-review-required ok-to-test Indicates a non-member PR verified by an org member that is safe to test. labels Jul 13, 2026
@codecov-commenter

codecov-commenter commented Jul 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 65.60%. Comparing base (a90f853) to head (6fdfd3b).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #310   +/-   ##
=======================================
  Coverage   65.60%   65.60%           
=======================================
  Files          23       23           
  Lines        1608     1608           
=======================================
  Hits         1055     1055           
  Misses        473      473           
  Partials       80       80           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@openshift-ci
openshift-ci Bot requested review from charlesgong and xiaoyu74 July 13, 2026 04:16
@openshift-ci

openshift-ci Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Hi @red-hat-konflux-kflux-prd-rh03[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch from 75364a3 to df28177 Compare August 3, 2026 04:07
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 chore(deps): update go-openapi packages to v1 - autoclosed Aug 3, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot deleted the konflux/mintmaker/master/major-go-openapi branch August 3, 2026 12:03
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 - autoclosed chore(deps): update go-openapi packages to v1 Aug 4, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch 2 times, most recently from df28177 to 5b77e6f Compare August 4, 2026 04:05
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch from 5b77e6f to 8dd7566 Compare August 31, 2026 04:07
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:08 AM UTC · Completed 4:16 AM UTC

Commit: 8dd7566 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.30

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Looks good to me

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 31, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch from 8dd7566 to 90fc974 Compare September 8, 2026 04:06
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 8, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:08 AM UTC · Completed 4:21 AM UTC

Commit: 90fc974 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.20

@openshift-ci

openshift-ci Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux-kflux-prd-rh03[bot]
Once this PR has been reviewed and has the lgtm label, please assign theautoroboto for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@fullsend-ai-review fullsend-ai-review Bot added the risk/low PR risk: low label Sep 8, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 8, 2026

Copy link
Copy Markdown

Risk Assessment: low (1/5)

Details

Low-risk dependency version bump by a bot. Two files changed (go.mod, go.sum) with 16 total lines. No protected paths, no security-sensitive files, no CI changes. Indirect dependencies (go-openapi/jsonpointer, go-openapi/jsonreference) bumped from v0.x to v1.x with confirmed API stability pledge.

Previous run

Risk Assessment: low (1/5)

Details

Low-risk dependency version bump by a bot. Two files changed (go.mod, go.sum) with 16 total lines. No protected paths, no security-sensitive files, no CI changes. Indirect dependencies (go-openapi/jsonpointer, go-openapi/jsonreference) bumped from v0.x to v1.x with confirmed API stability pledge.

fullsend-ai-review[bot]

This comment was marked as outdated.

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 chore(deps): update go-openapi packages to v1 - autoclosed Sep 11, 2026
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 11, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 8:04 AM UTC · Completed 8:14 AM UTC

Commit: 90fc974 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.50

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #310 — autoclosed MintMaker dependency bump

PR #310 was a bot-authored dependency update from Red Hat Konflux MintMaker, bumping go-openapi/jsonpointer (v0.24.0→v1.0.1) and go-openapi/jsonreference (v0.21.6→v1.0.2). The PR changed 16 lines across 2 files (go.mod and go.sum). It was created on Jul 13, went through a close/reopen/close cycle, received two full review agent runs, and was permanently autoclosed by the bot on Sep 11 without ever being merged.

Workflow timeline

Date Event
Jul 13 MintMaker bot creates PR, labels: area/dependency, major-update, manual-review-required, ok-to-test
Aug 3 Bot autoclosed PR, deleted branch
Aug 4 Bot reopened PR, force-pushed new commit
Aug 31 Bot force-pushed; review agent ran (opus, high effort, $1.30) → APPROVED, labeled ready-for-merge
Sep 8 Bot force-pushed; review agent ran (opus, high effort, $2.20) → APPROVED, labeled risk/low
Sep 11 Bot autoclosed PR permanently; retro dispatched

Cost and waste

Two full opus-tier review runs cost $3.50 for a 16-line dependency version bump that was never merged. Both reviews returned "Looks good to me" — technically correct assessments, but the effort was disproportionate to the change and ultimately wasted since the PR was autoclosed.

This PR is not an isolated case. The repo has 16+ autoclosed MintMaker dependency PRs following the same pattern (batch closures observed on May 28 and Sep 11, among others). The cumulative agent cost across these PRs is likely significant.

Review quality

The review agent's assessments were reasonable — the go-openapi v0→v1 transition is well-documented as API-stable. The risk assessment (low, 1/5) was appropriate. However, the PR had failing E2E tests (ci/prow/osd-gcp-e2e, ci/prow/rosa-sts-e2e) and was labeled manual-review-required by the bot itself, indicating the major version bump warranted human attention. No human ever reviewed the PR.

Existing issue coverage

All major improvement opportunities identified in this retro are already tracked by open issues in fullsend-ai/fullsend:

  • Skip/reduce retro for bot dependency PRs: #3951, #3833, #4006 — this retro itself is evidence of waste: the retro agent is analyzing a PR with minimal agent workflow to examine.
  • Use cheaper model for trivial bot PRs: #2842 — both reviews used opus at high effort for a 16-line lockfile change; sonnet would have been adequate.
  • Skip full pipeline for auto-closed bot PRs: #4989, #4177 — this repo's 16+ autoclosed dependency PRs demonstrate the scale of the problem.
  • Retro dedup for close/reopen/close cycles: #5226 — PR chore(deps): update go-openapi packages to v1 #310's close (Aug 3) / reopen (Aug 4) / close (Sep 11) cycle could trigger redundant retro runs.
  • PR state check before dispatch: #6725 — checking PR state before review dispatch could have prevented reviews on a PR heading toward autoclosure.
  • Serial bot PR pattern: #3985 — the 16+ autoclosed MintMaker PRs in this repo demonstrate the cumulative cost pattern.

Agents repo

Agent definitions resolved from fullsend-ai/agents@v0.38.0 (commit 48511880eaea). Platform dispatch from fullsend-ai/fullsend (commit 2db46c4).

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 - autoclosed chore(deps): update go-openapi packages to v1 Sep 14, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch 2 times, most recently from 90fc974 to bd6aa2f Compare September 14, 2026 04:07
@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 33704434-afd8-4f86-82e8-82b1446b236d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 14, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:09 AM UTC · Completed 4:21 AM UTC

Commit: bd6aa2f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.27

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 chore(deps): update go-openapi packages to v1 - autoclosed Sep 23, 2026
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 23, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 8:03 AM UTC · Completed 8:14 AM UTC

Commit: bd6aa2f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.38

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #310 — go-openapi dependency bump (never merged)

Timeline

Date Event Cost
Jul 13 MintMaker creates PR bumping go-openapi/jsonpointer v0.24→v1.0.1 and go-openapi/jsonreference v0.21→v1.0.2 (2 files, 16 lines). Labels: manual-review-required, major-update.
Aug 3 PR autoclosed by lifecycle bot
Aug 4 PR reopened
Aug 31 Review run 1: opus/high → approved, "Looks good to me" $1.30
Sep 8 Review run 2: opus/high → approved, risk: low (1/5) $2.20
Sep 11 Retro run 1: identified review waste, referenced 8 existing fullsend issues $1.50
Sep 14 Review run 3: opus/high → approved again. CI fails (osd-gcp-e2e, validate). $2.27
Sep 23 PR autoclosed. Retro run 2 dispatched (this run). ~$1.50

Total agent spend: ~$8.77 on a 16-line dependency bump that was never merged.

Assessment

This PR exemplifies a well-documented waste pattern: opus-tier agent reviews running repeatedly on trivial bot-authored dependency PRs that are never merged. Every finding from this retro is already covered by existing open issues. The previous retro (Sep 11) identified the same problems and referenced the same issues — yet the third review ($2.27) still ran three days later, and this second retro was dispatched on the same PR.

Evidence for existing issues

  • fullsend-ai/fullsend #7583 and fullsend-ai/agents #257: Three opus/high reviews at $5.77 total for zero findings on a 16-line dep bump. All three returned "Looks good to me." Implementing either skip or downgrade for bot dependency PRs would have saved the full amount.
  • fullsend-ai/fullsend #4006: This retro run itself is evidence — retro dispatched on an automated dependency PR provides no novel insight over the first retro run.
  • fullsend-ai/fullsend #2401 and #5226: Second retro on the same PR, finding identical problems. The close/reopen/close lifecycle triggered a duplicate retro dispatch.
  • fullsend-ai/fullsend #1355: MintMaker rebased the PR twice (commits 8dd756690fc974bd6aa2f), each rebase triggering a new review despite no semantic change in the diff.
  • openshift/ocm-agent-operator #342: This PR is another instance of the pattern — major-version bump of indirect Go dependencies that will never auto-merge. Suppressing these at the Renovate config level would prevent the PR from being created at all.
  • openshift/ocm-agent-operator #359: The retro agent hit the stop-prek-validation hook repeatedly despite being read-only.
  • fullsend-ai/agents #501: PR has contradictory labels ready-for-merge and manual-review-required simultaneously — the post-review script applied ready-for-merge after agent approval without checking for the Renovate-applied manual-review-required label.

No new proposals

All improvement opportunities identified in this retro are covered by existing open issues across fullsend-ai/fullsend, fullsend-ai/agents, and openshift/ocm-agent-operator. Implementing the highest-impact subset — bot-dependency review skip (#7583 / #257), retro dedup (#2401), and Renovate major-bump suppression (#342) — would have prevented ~$8.77 of waste on this PR alone.

Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update go-openapi packages to v1 - autoclosed chore(deps): update go-openapi packages to v1 Sep 24, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/major-go-openapi branch from bd6aa2f to 6fdfd3b Compare September 24, 2026 04:06
@openshift-ci

openshift-ci Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

@red-hat-konflux-kflux-prd-rh03[bot]: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/validate bd6aa2f link true /test validate

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Issues or PRs related to dependency changes major-update manual-review-required ok-to-test Indicates a non-member PR verified by an org member that is safe to test. ready-for-merge All reviewers approved — ready to merge risk/low PR risk: low

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant