Skip to content

chore(deps): update dependency virtualenv to v21.14.6 - #730

Merged
castrojo merged 2 commits into
mainfrom
renovate/virtualenv-21.x
Oct 10, 2026
Merged

castrojo merged 2 commits into
mainfrom
renovate/virtualenv-21.x

Conversation

@mergeraptor

@mergeraptor mergeraptor Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
virtualenv (changelog) 21.13.0 → 21.14.5 age confidence

Release Notes

pypa/virtualenv (virtualenv)

v21.14.5

Compare Source

What's Changed

Full Changelog: pypa/virtualenv@21.14.4...21.14.5

v21.14.4

Compare Source

What's Changed

Full Changelog: pypa/virtualenv@21.14.3...21.14.4

v21.14.3

Compare Source

What's Changed

Full Changelog: pypa/virtualenv@21.14.2...21.14.3

v21.14.2

Compare Source

What's Changed

Full Changelog: pypa/virtualenv@21.14.1...21.14.2

v21.14.1

Compare Source

What's Changed

Full Changelog: pypa/virtualenv@21.14.0...21.14.1

v21.14.0

Compare Source

What's Changed

New Contributors

Full Changelog: pypa/virtualenv@21.13.0...21.14.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This bump cannot land as-is: validate fails because virtualenv==21.14.2 declares a new runtime dependency, packaging>=23.1, and requirements-ci.lock has no packaging entry. With pip install --require-hashes -r requirements-ci.lock (the Static hygiene step), pip refuses any transitive requirement that isn't pinned and hashed:

Collecting packaging>=23.1 (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))
ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not:
    packaging>=23.1 … (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))

(job 110367457364; identical failure on the earlier run 110367421005.)

requirements-ci.lock:111 is the only line Renovate changed; grep -n '^packaging' requirements-ci.lock at head 1a60858 returns nothing. Renovate's lockfile-maintenance for this file type only rewrites the one pin, so it will keep re-pushing the same broken state.

Fix is a lockfile regeneration, not a Renovate retry: rerun the command in requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13 -) so packaging gets a pinned, hashed entry alongside virtualenv==21.14.2. Someone with push access to this branch (or a fresh PR) needs to do that; I have not changed anything. #729 (filelock 4.0.8) is unaffected — its validate is green.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Hive filed out-of-scope review findings as backlog issues so they do not block this PR:

Cap: 3 backlog issue(s) per PR.

@hivecommons-hive

hivecommons-hive Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🐝 Superseded regeneration series

mergeraptor[bot] has 2 open PRs regenerating the same file(s). This one is the newest, so the 1 older one(s) are superseded by construction:

Posted once on the newest PR rather than on each of them, so a daily regeneration does not produce a daily comment on every PR in the series.

Evidence — identical changed-file set (1 file(s)):

  • requirements-ci.lock

This is a suggestion, not a verdict. Hive will not close, label, approve or merge anything here — a human decides.

It was produced by comparing changed-file sets across open PRs, which is a candidate generator: PRs that share a file are not necessarily the same work. Here the patches DIFFER, so this is the weaker tier: dependency-bump PRs that edit one shared manifest, and unrelated fixes to one busy file, both land in it. Read the diffs before acting.

@hivecommons-hive hivecommons-hive Bot added the 3-human-queue Work admitted to the human-maintained queue. label Oct 1, 2026
@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from 1a60858 to 2fdbe92 Compare October 1, 2026 15:19

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HUMAN DECISION NEEDED — merge is blocked until requirements-ci.lock is regenerated with the new packaging transitive pin; decide whether to regenerate on this branch or let Renovate re-roll.

correctness

  • Lock is incomplete; CI install fails (requirements-ci.lock:111). virtualenv 21.14.2 adds a new runtime dependency packaging>=23.1 (PyPI requires_dist; absent in 21.13.0). The diff bumps only the virtualenv== line, so python -m pip install --require-hashes -r requirements-ci.lock (.github/workflows/validate.yml:43, .github/workflows/publish-contribute.yml:56) aborts with "In --require-hashes mode, all requirements must have their versions pinned" — both validate checks on this PR fail for exactly that. Fix: uv pip compile --generate-hashes --python-version 3.13 per the header at requirements-ci.lock:2 so a hashed packaging== entry is added.

style (out-of-scope, backlog)

  • scripts/update-requirements-ci-hashes.mjs:12-49 only refreshes hashes for existing == lines (REQUIREMENT_START_PATTERN), so the renovate-hashes.yml repair step (.github/workflows/renovate-hashes.yml:127) cannot add newly introduced transitive deps; any upstream dep that grows a requirement will break the lock this way again.

No findings from: security, intent-alignment (linked issue #8203 does not exist in this repo; judged against the PR title/body instead), docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • requirements-ci.lock:111 bumps virtualenv to 21.14.2 but the lock has no entry for its new runtime dependency packaging>=23.1 (added in virtualenv 21.14.0, pypa/virtualenv#3361). CI validate job runs pip install --require-hashes -r requirements-ci.lock and fails: "In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 from … (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))" (runs 36906602210, 36906594794). scripts/update-requirements-ci-hashes.mjs only refreshes hashes for pins already present, so the renovate hash-repair cannot add the missing transitive pin. Fix: regenerate the lock with the tool named in requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13) so packaging==<ver> with hashes and # via virtualenv is added.

intent-alignment

  • The PR's closing keyword references projectbluefin/contribute#8203, which does not resolve (gh issue view 8203 → "Could not resolve to an issue"). Contract cannot be verified; treating the Renovate update itself as the intent.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from 6a42249 to 7cec50f Compare October 1, 2026 21:18

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • Lock missing new transitive dep packaging — requirements-ci.lock:111 bumps virtualenv==21.14.2, whose requires_dist adds packaging>=23.1 (not required by 21.13.0). The lock pins no packaging entry, so python -m pip install --require-hashes -r requirements-ci.lock (validate job) fails: ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 from virtualenv==21.14.2. Both validate checks are red (jobs 110589315568, 110589316166). Fix: regenerate the lock (uv pip compile --generate-hashes --python-version 3.13, per requirements-ci.lock:2) so packaging==<ver> with hashes is added; the hash-repair task only refreshes existing pins and cannot add a new package.

intent-alignment

  • Closing reference #8203 does not resolve to an issue in this repo (gh issue view fails); reviewed against the PR body (plain Renovate bump) instead.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from 7cec50f to 4291e11 Compare October 2, 2026 00:41
@mergeraptor mergeraptor Bot changed the title chore(deps): update dependency virtualenv to v21.14.2 chore(deps): update dependency virtualenv to v21.14.3 Oct 2, 2026

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • validate fails: lock is missing virtualenv's new transitive dep packaging (requirements-ci.lock:111-114). virtualenv 21.14.0+ declares packaging>=23.1 as a runtime requirement (added by pypa/virtualenv#3361, "compare wheel versions with PEP 440"); 21.13.0 did not. This PR only rewrote the virtualenv== line and its two --hash lines, so pip install --require-hashes -r requirements-ci.lock (.github/workflows/validate.yml, "Run set -euo pipefail" step) aborts with In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 — see job 110652122914. The refresh job passed because scripts/update-requirements-ci-hashes.mjs only re-fetches hashes for lines already present (parseRequirement/fetchPackageHashes, lines 22-78); it never recompiles the dependency set, so new transitive deps are invisible to it.
    Fix: recompile per the header on requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13) or add a packaging==<ver> block with both PyPI sha256 hashes and # via virtualenv.

No findings from: security, intent-alignment, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch 3 times, most recently from 0bdf58d to 5a6930c Compare October 2, 2026 06:28

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • CI install broken — new transitive dep packaging missing from lock (high). virtualenv 21.14.3 adds packaging>=23.1 to requires_dist (21.13.0 did not). requirements-ci.lock has no packaging entry (entries at lines 3–111 are cfgv, distlib, filelock, identify, nodeenv, platformdirs, pre-commit, python-discovery, pyyaml, virtualenv), so .github/workflows/validate.yml:43 (pip install --require-hashes -r requirements-ci.lock) fails: ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 (from virtualenv==21.14.3->-r requirements-ci.lock (line 111)) (job 110732884496). publish-contribute.yml runs the same install. Fix: regenerate per the header at requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13) so packaging==<ver> with hashes is added.
  • Out-of-scope: scripts/update-requirements-ci-hashes.mjs / renovate-hashes.yml only rewrite hashes for existing name==version lines, so any upstream bump that introduces a new transitive dependency will keep breaking this way; worth a follow-up to detect missing transitive pins.

intent-alignment

  • Info: the review contract cites issue #8203 but gh issue view 8203 returns "Could not resolve", and the PR body has no closing keyword. Judged against the PR title instead; the diff (lines 111–113) is exactly the stated bump. Hashes verified against PyPI for virtualenv-21.14.3-py3-none-any.whl and .tar.gz.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from 5a6930c to f312861 Compare October 2, 2026 09:20

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • Lockfile missing new transitive dep packaging — validate CI fails. virtualenv 21.14.3 adds packaging>=23.1 to its Requires-Dist (21.13.0 did not have it). The PR only rewrote the pin/hashes at requirements-ci.lock:111-113; no packaging==… entry was added. .github/workflows/validate.yml:43 runs python -m pip install --require-hashes -r requirements-ci.lock, which aborts: ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 (from virtualenv==21.14.3) (run 36989252630). Fix: regenerate the lock per its header (requirements-ci.lock:2: uv pip compile --generate-hashes --python-version 3.13 -) so packaging is pinned with hashes.
  • (out-of-scope, tooling) scripts/update-requirements-ci-hashes.mjs:30-78 only refreshes hashes for packages already listed in the lock; it cannot add transitive deps a new upstream version introduces, so the renovate-hashes.yml backstop described at docs/skills/image-build.md:119-124 passes (refresh ✅) while the lock is still unbuildable. Worth a follow-up to recompile instead of hash-patch.

intent-alignment

  • (out-of-scope, info) Linked contract projectbluefin/contribute#8203 does not resolve (gh issue view 8203 → not found); diff was judged against the PR title/body, which it matches apart from the missing dep above.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • Lock is incomplete; CI validate fails on install. requirements-ci.lock:111 bumps virtualenv==21.14.3, which (unlike 21.13.0) declares packaging>=23.1 as a runtime dependency. The lock has no packaging entry, so python -m pip install --require-hashes -r requirements-ci.lock aborts with ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 (job 110836837650). Renovate's version-only bump + hash refresh (scripts/update-requirements-ci-hashes.mjs) cannot add new transitive deps. Fix: regenerate the lock with the documented command in requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13) so packaging==<ver> with hashes is added under # via virtualenv.

intent-alignment

  • Closing-keyword issue projectbluefin/contribute#8203 does not resolve (gh issue view → not found); contract judged against the PR title (dependency bump) instead.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from bd17f52 to 3d8c8e8 Compare October 2, 2026 15:20
@mergeraptor mergeraptor Bot changed the title chore(deps): update dependency virtualenv to v21.14.3 chore(deps): update dependency virtualenv to v21.14.4 Oct 2, 2026

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correctness

  • requirements-ci.lock:111 bumps virtualenv 21.13.0 → 21.14.4, but virtualenv 21.14.x adds a new runtime dependency packaging>=23.1 (PyPI requires_dist; absent in 21.13.0). The lock has no packaging entry, so pip install --require-hashes -r requirements-ci.lock (validate / Static hygiene job) fails: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1. Both validate runs on this head fail (runs 37026314817, 37026323567). The hash-repair workflow only refreshes hashes for existing pins; it cannot add a transitive. Fix: regenerate the lock per its header (uv pip compile --generate-hashes --python-version 3.13) so a pinned+hashed packaging line (# via virtualenv) is added.

intent-alignment

  • Closing-keyword contract #8203 does not resolve in projectbluefin/contribute (gh issue view 8203 → not found); judged against the PR title only.

No findings from: security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 high finding

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@mergeraptor
mergeraptor Bot force-pushed the renovate/virtualenv-21.x branch from 3d8c8e8 to 656fb1b Compare October 2, 2026 18:23
@mergeraptor mergeraptor Bot changed the title chore(deps): update dependency virtualenv to v21.14.4 chore(deps): update dependency virtualenv to v21.14.5 Oct 2, 2026
@renovate
renovate Bot force-pushed the renovate/virtualenv-21.x branch 2 times, most recently from 840ebc9 to 0106f17 Compare October 7, 2026 21:21

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@renovate
renovate Bot force-pushed the renovate/virtualenv-21.x branch from c81f5d2 to 7134bd3 Compare October 8, 2026 00:41

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@renovate
renovate Bot force-pushed the renovate/virtualenv-21.x branch 2 times, most recently from 41fc67b to 50d926f Compare October 8, 2026 03:37

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@renovate
renovate Bot force-pushed the renovate/virtualenv-21.x branch from dac606e to daa310b Compare October 8, 2026 04:40

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@renovate
renovate Bot force-pushed the renovate/virtualenv-21.x branch from 395414f to 43ddae4 Compare October 8, 2026 06:30

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • info: Review contract cites projectbluefin/contribute#8203, but gh issue view 8203 returns "Could not resolve to an issue"; the PR body carries no closing keyword. Judged against the PR's own stated intent (virtualenv 21.13.0 → 21.14.5), which the diff fully matches (requirements-ci.lock:115-117). Added transitive packaging==26.3 (requirements-ci.lock:25-28) is required by virtualenv 21.14.5 (packaging>=23.1); both hashes match PyPI. python-discovery==1.6.1 (requirements-ci.lock:36-39) already satisfies the new python-discovery>=1.6 requirement.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • (low) PR title/body say virtualenv 21.14.5 and the release notes stop at 21.14.5, but the lock pins virtualenv==21.14.6 (requirements-ci.lock:115, already in the first commit 82a34ef). Hashes verified against PyPI for 21.14.6 wheel+sdist (lock:116-117), and transitive pins satisfy its metadata (packaging==26.3 lock:25, python-discovery==1.6.1 lock:36, distlib==0.4.3 lock:7). Content is fine; title/body should be refreshed so the 21.14.6 changes are what reviewers see.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • (low) PR title/body describe 21.14.5, but requirements-ci.lock:115 pins virtualenv==21.14.6 (Renovate commit f3f9c0d is already titled 21.14.6; 21.14.6 shipped 2026-10-08 14:49 UTC). Body release notes stop at 21.14.5, so the 21.14.6 changes (pypa/virtualenv#3378–#3383, CI + embed-log read guard) are not surfaced. Hashes at requirements-ci.lock:116-117 and packaging==26.3 at :25-27 match PyPI; python-discovery==1.6.1 (:36) satisfies the new >=1.6.1 floor; validate (workflow_dispatch) passed on baef075. Title will self-correct on next Renovate rebase — not blocking.

Note: the linked contract issue #8203 does not resolve in this repo (gh issue view 8203 → not found); intent judged against the PR body.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • (low) PR title/body say virtualenv → 21.14.5, but requirements-ci.lock:115 pins virtualenv==21.14.6 (and the Renovate commit on the branch is "update dependency virtualenv to v21.14.6"). The title/body are stale relative to the diff; the merged state will be 21.14.6. The linked contract issue #8203 could not be resolved (gh issue view → not found), so intent was judged from the diff and commit messages only.

Verified independently against PyPI: virtualenv 21.14.6 wheel/sdist sha256 and packaging 26.3 wheel/sdist sha256 match requirements-ci.lock:25-27,115-117; packaging>=26.3 is a new requirement of virtualenv 21.14.x and is present with # via virtualenv. No CI checks were reported on the branch at review time.

No findings from: correctness, security, style, docs-currency.

Confidence: 3/5 (needs attention) — 1 perspective requested changes

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Title updated to match the diff: requirements-ci.lock pins virtualenv==21.14.6 (Renovate body table still reads 21.14.5 from the original branch creation; lockfile/hashes are for 21.14.6, which also adds packaging==26.3 as a new virtualenv dependency). No code change required.

Hive-Fix-Attempt: 1/6


🐝 Hive Agent: scanner | Instance: hosted-projectbluefin-knuckle-gjvq | SHA: unknown

— hive: agent=scanner backend=copilot model=claude-opus-5.5 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • info: PR body table says 21.13.0 → 21.14.5, but the diff pins virtualenv==21.14.6 (requirements-ci.lock:115) and the title says v21.14.6. Stale Renovate body; the lock is what ships. Hashes at requirements-ci.lock:116-117 and the new packaging==26.3 pin (requirements-ci.lock:25-27) match PyPI, and 21.14.6's requirements (packaging>=26.3, python-discovery>=1.6.1, filelock, platformdirs, distlib) are all satisfied by existing pins.
  • info: the linked contract issue #8203 does not resolve in this repo (gh issue view 8203 → not found) and the PR carries no closing reference; judged against the PR's own stated purpose.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

docs-currency

  • info: PR body table and release notes stop at 21.13.0 → 21.14.5, while requirements-ci.lock:115 pins virtualenv==21.14.6 (title matches the lock). Body is stale by one patch; Renovate will normally refresh it on the next rebase.

No findings from: correctness, security, intent-alignment, style.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • info: PR body's update table and release notes stop at 21.13.0 → 21.14.5, but requirements-ci.lock:115 pins virtualenv==21.14.6 (recompiled by renovate-hashes.yml in 4f92202). Title matches the lock; body is stale. Not blocking — the 21.14.6 sdist/wheel sha256 in requirements-ci.lock:116-117 and packaging==26.3 in :25-27 match PyPI, and the dispatched validate run on this head passed.
  • Linked issue #8203 does not resolve in this repo; intent judged against the PR title/diff.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

docs-currency

  • PR body is stale: table and release notes stop at 21.13.0 → 21.14.5, but the diff pins virtualenv==21.14.6 (requirements-ci.lock:115). Renovate rebased the branch without regenerating the body; the 21.14.6 release notes are not shown. Non-blocking — hashes at requirements-ci.lock:116-117 match the PyPI sdist/wheel for 21.14.6, and packaging==26.3 (requirements-ci.lock:25-27) satisfies the new packaging>=26.3 requirement with matching hashes.

intent-alignment

  • The closing-keyword issue projectbluefin/contribute#8203 does not resolve (gh issue view 8203 → not found). The diff itself is a pure lock bump matching the PR title, so this is a metadata issue, not a scope problem.

No findings from: correctness, security, style.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

intent-alignment

  • (low) PR body table and release notes stop at 21.13.0 → 21.14.5, but the title and requirements-ci.lock:115 pin virtualenv==21.14.6. Body is stale from a Renovate re-push; the diff is the authoritative bump. Hashes at requirements-ci.lock:116-117 and the new packaging==26.3 pin at :25-27 match PyPI for 21.14.6 / 26.3. The closing-keyword reference #8203 does not resolve in this repo, so no issue contract was available to judge against.

No findings from: correctness, security, style, docs-currency.

Confidence: 5/5 (safe)

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

renovate Bot and others added 2 commits October 10, 2026 00:43
Renovate bumped the pinned version but could not run the post-upgrade
task that recompiles the lockfile, so its --hash lines and any newly
required dependency were missing and pip --require-hashes rejected it.
Recompiled with uv by scripts/update-requirements-ci-hashes.mjs in
https://github.com/projectbluefin/contribute/actions/runs/38010273563.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3-human-queue Work admitted to the human-maintained queue. agent/scanner Filed or owned by the scanner agent. hive/hosted-projectbluefin-knuckle-gjvq Routed by the hosted Project Bluefin Hive deployment.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant