What happened
cbusillo/odoo-tenant-cm-website#108 (a Dependabot cooldown change) failed its build job (run 36660624593):
Artifact publish requires odoo-devkit commit 74f4cf7 to be advertised by a ref in cbusillo/odoo-devkit.
74f4cf7 was devkit's main tip until #137 merged through the merge train (f3defeb9, 2026-09-30). It's still an ancestor of main, but no longer the tip of any ref. The last passing build was 2026-09-29 19:11 on main.
Why
odoo_devkit/local_runtime.py checks provenance with git ls-remote, which lists only ref tips. The documented intent (docs/tooling/artifact-inputs.md) is that "each recorded source commit must also be advertised by a ref in its normalized GitHub origin", so that a local commit can't be reattributed to another repository. Checking against tips only is stricter than that intent: every merge to devkit main breaks the next artifact build of every tenant that pins the previous tip, until each pin moves.
Suggested fix
Accept a commit that is reachable from an advertised ref. For example, fetch the advertised refs and check git merge-base --is-ancestor <commit> <ref>, or ask the GitHub API whether <ref> contains the commit. This keeps the provenance guarantee (the commit is published in that origin) without coupling tenants to devkit's current tip.
Left for the owners of the build-provenance work (cbusillo/launchplane#2602). cm-website#108 waits on this or on a devkit pin bump.
What happened
cbusillo/odoo-tenant-cm-website#108 (a Dependabot cooldown change) failed its
buildjob (run 36660624593):74f4cf7was devkit'smaintip until #137 merged through the merge train (f3defeb9, 2026-09-30). It's still an ancestor ofmain, but no longer the tip of any ref. The last passingbuildwas 2026-09-29 19:11 onmain.Why
odoo_devkit/local_runtime.pychecks provenance withgit ls-remote, which lists only ref tips. The documented intent (docs/tooling/artifact-inputs.md) is that "each recorded source commit must also be advertised by a ref in its normalized GitHub origin", so that a local commit can't be reattributed to another repository. Checking against tips only is stricter than that intent: every merge to devkitmainbreaks the next artifact build of every tenant that pins the previous tip, until each pin moves.Suggested fix
Accept a commit that is reachable from an advertised ref. For example, fetch the advertised refs and check
git merge-base --is-ancestor <commit> <ref>, or ask the GitHub API whether<ref>contains the commit. This keeps the provenance guarantee (the commit is published in that origin) without coupling tenants to devkit's current tip.Left for the owners of the build-provenance work (cbusillo/launchplane#2602). cm-website#108 waits on this or on a devkit pin bump.