Confirmed release gap
Main go.mod still requires all four cloud-commitments-go modules (pkg, providers/aws, providers/azure, providers/gcp) at v0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. It therefore does not select the subsequent GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.
These coordinated old pins compile. The provider-only compilation failure was fixed in the library; upgrading that repository does not update the MCP consumer automatically.
References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144.
Scope
Update the four requirements and corresponding sums together to published merged commit a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve and verify canonical public versions/source hashes. No replacements, vendoring, unrelated upgrades, source refactors or release automation. Add only regressions needed for consumer adoption; no cloud purchases or deployment.
Acceptance
- With the CI-pinned toolchain and GOWORK=off, record all four selected library versions with no replacements; tidy-diff, vet and pinned lint pass.
- Build the real MCP server target (
make build or the repository's current server command) and run server/tools race-short tests.
- Drive the actual MCP protocol with an in-process/fake-cloud harness, exercising tool registration, recommendation retrieval/filtering and purchase-result serialization. Recent matching GCP CUDs must suppress repeat recommendations; verify nullable versus explicit-zero purchase cost survives tool output and existing purchase/error guards remain intact.
- Prove an applicable consumer regression fails at the old pins and passes after upgrade. Do not execute live cloud purchases.
- Record independently reviewed SHA and verification. Treat packaging/release/deployment as separate status, not implied by merge.
Triage
P2 / medium / this-sprint / few / small: the dependency gap is confirmed, but this task has not reproduced an MCP-specific repeat purchase or established deployment exposure. The upstream P1 financial-risk fix needs adoption; raise this consumer's priority if protocol-path reproduction establishes the corresponding risk.
Confirmed release gap
Main
go.modstill requires all four cloud-commitments-go modules (pkg,providers/aws,providers/azure,providers/gcp) atv0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. It therefore does not select the subsequent GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.These coordinated old pins compile. The provider-only compilation failure was fixed in the library; upgrading that repository does not update the MCP consumer automatically.
References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144.
Scope
Update the four requirements and corresponding sums together to published merged commit
a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve and verify canonical public versions/source hashes. No replacements, vendoring, unrelated upgrades, source refactors or release automation. Add only regressions needed for consumer adoption; no cloud purchases or deployment.Acceptance
make buildor the repository's current server command) and run server/tools race-short tests.Triage
P2 / medium / this-sprint / few / small: the dependency gap is confirmed, but this task has not reproduced an MCP-specific repeat purchase or established deployment exposure. The upstream P1 financial-risk fix needs adoption; raise this consumer's priority if protocol-path reproduction establishes the corresponding risk.