Skip to content

fix(deps): adopt reviewed cloud-commitments-go purchase safeguards #35

Description

@cristim

Confirmed release gap

Main go.mod still requires all four cloud-commitments-go modules (pkg, providers/aws, providers/azure, providers/gcp) at v0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. It therefore does not select the subsequent GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.

These coordinated old pins compile. The provider-only compilation failure was fixed in the library; upgrading that repository does not update the MCP consumer automatically.

References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144.

Scope

Update the four requirements and corresponding sums together to published merged commit a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve and verify canonical public versions/source hashes. No replacements, vendoring, unrelated upgrades, source refactors or release automation. Add only regressions needed for consumer adoption; no cloud purchases or deployment.

Acceptance

  • With the CI-pinned toolchain and GOWORK=off, record all four selected library versions with no replacements; tidy-diff, vet and pinned lint pass.
  • Build the real MCP server target (make build or the repository's current server command) and run server/tools race-short tests.
  • Drive the actual MCP protocol with an in-process/fake-cloud harness, exercising tool registration, recommendation retrieval/filtering and purchase-result serialization. Recent matching GCP CUDs must suppress repeat recommendations; verify nullable versus explicit-zero purchase cost survives tool output and existing purchase/error guards remain intact.
  • Prove an applicable consumer regression fails at the old pins and passes after upgrade. Do not execute live cloud purchases.
  • Record independently reviewed SHA and verification. Treat packaging/release/deployment as separate status, not implied by merge.

Triage

P2 / medium / this-sprint / few / small: the dependency gap is confirmed, but this task has not reproduced an MCP-specific repeat purchase or established deployment exposure. The upstream P1 financial-risk fix needs adoption; raise this consumer's priority if protocol-path reproduction establishes the corresponding risk.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions