Skip to content

fix(deps): adopt reviewed cloud-commitments-go purchase safeguards #2121

Description

@cristim

Confirmed release gap

Main go.mod still requires all four cloud-commitments-go modules (pkg, providers/aws, providers/azure, providers/gcp) at v0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. This predates the merged GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.

The coordinated old pins compile, so this is not a claim that the CLI currently has the standalone provider compile error. Updating the library repository alone does not deliver its newer behavior to this CLI.

References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144. #144 explains why recent GCP commitments failed to suppress later recommendations before the library fix.

Scope

Update the four library requirements and corresponding sums together to published merged commit a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve each canonical module version and confirm source hashes. Do not use local replacements, vendor copies, branch-only unpublished revisions, unrelated upgrades or release automation. Add only consumer regressions necessary to verify the adopted behavior; this issue does not authorize cloud purchases or deployment.

Acceptance

  • With the repository CI-pinned toolchain and GOWORK=off, capture all four selected library module versions with no replacements. Require tidy-diff, vet and pinned lint to pass.
  • Build the actual CLI using make build or go build -o <temporary-output> ./cmd; run the command package race/short suite.
  • Exercise recommendation-to-purchase filtering through the CLI's actual entry path with fake cloud boundaries: a recent matching GCP CUD suppresses the retry, recent unknown AWS reservation states remain owned, and Redis/Valkey or missing ElastiCache engine matching uses the updated policy. Preserve explicit-zero versus absent purchase cost through output and fail-closed interruption/retry behavior.
  • Show an applicable new regression fails with the old pins and passes with the new pins. Do not invoke real purchases or --yes.
  • Record the reviewed commit, checks and artifact/release status without claiming deployment from a merged dependency change.

Triage

P2 / medium / this-sprint / few / small: older dependency pins are confirmed, but no live incident or consumer-specific failing purchase path has been reproduced in this tracking task. The upstream P1 financial-risk fix warrants timely adoption; its label is not automatically evidence for a consumer P1. Reassess severity/priority if end-to-end reproduction confirms repeat-purchase exposure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions