Confirmed release gap
Main go.mod still requires all four cloud-commitments-go modules (pkg, providers/aws, providers/azure, providers/gcp) at v0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. The platform therefore does not select the subsequent GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.
The coordinated old pins compile; this is an adoption gap, not evidence that current platform builds suffer the provider-only compile failure. Library merges do not update an existing platform binary or deployment.
References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144.
Scope
Update the four requirements and corresponding sums together to published merged commit a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve each canonical public version and verify source hashes. No replacements, vendoring, unrelated dependency upgrades, schema migrations or speculative release automation. Consumer regression coverage is in scope; deployment and real purchases are not authorized by this issue.
Acceptance
- With the CI-pinned toolchain and GOWORK=off, capture all four resolved module versions with no replacements; build the actual server, run tidy-diff, vet and pinned lint.
- Run affected API, provider-integration and purchase-engine race/short tests. Use fake cloud boundaries and local database fixtures where the actual path persists purchase results.
- Trace the actual recommendation/purchase API through filtering and response/storage: recent matching GCP CUDs suppress repeat purchases; applicable AWS/ElastiCache ownership/engine safeguards remain active; nullable and explicit-zero costs preserve the platform's persistence/API behavior.
- Prove an applicable consumer regression fails on the old pins and passes after upgrade. Verify tenant/account boundaries remain intact. If UI-observable data changes, exercise the affected local UI path.
- Record exact reviewed SHA and evidence. No production deployment, cloud purchase, migration or live incident is implied by a successful dependency-update PR.
Triage
P2 / medium / this-sprint / few / medium effort: the stale dependency graph is confirmed and adoption crosses API/purchase/persistence boundaries. This tracking task has not established a deployed incident or reproduced a platform-specific duplicate purchase. The upstream P1 financial-risk fix makes adoption worthwhile; raise severity/priority if actual consumer-path reproduction establishes that exposure.
Confirmed release gap
Main
go.modstill requires all four cloud-commitments-go modules (pkg,providers/aws,providers/azure,providers/gcp) atv0.0.0-20260928214714-ce9513612901, verified on 2026-09-30. The platform therefore does not select the subsequent GCP commitment-family dedupe, AWS reservation-state, ElastiCache engine-dedupe and purchase-cost fixes.The coordinated old pins compile; this is an adoption gap, not evidence that current platform builds suffer the provider-only compile failure. Library merges do not update an existing platform binary or deployment.
References: library #154, merged provider pin/standalone CI PR #159, and P1 GCP duplicate-purchase issue #144.
Scope
Update the four requirements and corresponding sums together to published merged commit
a32fd1a178e971ba48ae7469f5d472e6391c68e2, or a later independently reviewed canonical release containing it. Resolve each canonical public version and verify source hashes. No replacements, vendoring, unrelated dependency upgrades, schema migrations or speculative release automation. Consumer regression coverage is in scope; deployment and real purchases are not authorized by this issue.Acceptance
Triage
P2 / medium / this-sprint / few / medium effort: the stale dependency graph is confirmed and adoption crosses API/purchase/persistence boundaries. This tracking task has not established a deployed incident or reproduced a platform-specific duplicate purchase. The upstream P1 financial-risk fix makes adoption worthwhile; raise severity/priority if actual consumer-path reproduction establishes that exposure.