Skip to content

Artifact publish rejects a pinned devkit commit once it stops being a ref tip #139

Description

@shiny-code-app

What happened

cbusillo/odoo-tenant-cm-website#108 (a Dependabot cooldown change) failed its build job (run 36660624593):

Artifact publish requires odoo-devkit commit 74f4cf7 to be advertised by a ref in cbusillo/odoo-devkit.

74f4cf7 was devkit's main tip until #137 merged through the merge train (f3defeb9, 2026-09-30). It's still an ancestor of main, but no longer the tip of any ref. The last passing build was 2026-09-29 19:11 on main.

Why

odoo_devkit/local_runtime.py checks provenance with git ls-remote, which lists only ref tips. The documented intent (docs/tooling/artifact-inputs.md) is that "each recorded source commit must also be advertised by a ref in its normalized GitHub origin", so that a local commit can't be reattributed to another repository. Checking against tips only is stricter than that intent: every merge to devkit main breaks the next artifact build of every tenant that pins the previous tip, until each pin moves.

Suggested fix

Accept a commit that is reachable from an advertised ref. For example, fetch the advertised refs and check git merge-base --is-ancestor <commit> <ref>, or ask the GitHub API whether <ref> contains the commit. This keeps the provenance guarantee (the commit is published in that origin) without coupling tenants to devkit's current tip.

Left for the owners of the build-provenance work (cbusillo/launchplane#2602). cm-website#108 waits on this or on a devkit pin bump.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions