Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .consumers/encrypt/v5.1.10/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This consumer snapshot has accompanying metadata.json containing the pubspec SHA and the discovered runtime_ci_tooling constraint. Updating the constraint here without regenerating/updating that metadata will leave .consumers inconsistent.

Suggested change
version: ^0.14.1

Copilot uses AI. Check for mistakes.
lints: ^6.0.0
test: ^1.24.0

Expand Down
2 changes: 1 addition & 1 deletion .consumers/grpc-dart/v5.3.6/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This .consumers pubspec sits next to a generated metadata.json that records the pubspec SHA and discovered runtime_ci_tooling constraint. After changing the constraint here, regenerate/update the snapshot metadata so .consumers remains internally consistent.

Suggested change
version: ^0.14.1
version: ^0.14.0

Copilot uses AI. Check for mistakes.

# ==========================================================================
# Direct pub.dev dev dependencies
Expand Down
6 changes: 3 additions & 3 deletions .consumers/mindfck/v0.0.15/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,14 +19,14 @@ dependencies:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8

dev_dependencies:
runtime_ci_tooling:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The .consumers directory appears to be generated from consumer discovery/release sync and includes metadata.json with the pubspec SHA + discovered runtime_ci_tooling constraint. Changing the constraint here without regenerating/updating that metadata leaves the snapshot inconsistent.

Suggested change
version: ^0.14.1

Copilot uses AI. Check for mistakes.
build_runner: ^2.11.0
test: ^1.24.0
leak_tracker: ^11.0.1
Expand All @@ -35,7 +35,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/encrypt.git
tag_pattern: v{{version}}
version: ^5.1.11
version: ^6.0.0
cli_script:
git:
url: git@github.com:open-runtime/dart_cli_script.git
Expand Down
8 changes: 4 additions & 4 deletions .consumers/runtime_aot_client_examples/v0.0.3/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -43,17 +43,17 @@ dependencies:
git:
url: git@github.com:open-runtime/encrypt.git
tag_pattern: v{{version}}
version: ^5.1.11
version: ^6.0.0
grpc:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8
runtime_isomorphic_library:
git:
url: git@github.com:open-runtime/runtime_isomorphic_library.git
tag_pattern: v{{version}}
version: ^1.2.6
version: ^3.0.0
runtime_mindfck:
git:
url: git@github.com:open-runtime/mindfck.git
Expand All @@ -75,7 +75,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This .consumers pubspec is a snapshot that has associated metadata (pubspec SHA + discovered runtime_ci_tooling constraint). Since the constraint is changed here, please regenerate/update the snapshot metadata to avoid stale .consumers state.

Suggested change
version: ^0.14.1
version: ^0.14.0

Copilot uses AI. Check for mistakes.

# ==========================================================================
#
Expand Down
8 changes: 4 additions & 4 deletions .consumers/runtime_aot_tooling/v1.0.2/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,17 +32,17 @@ dependencies:
git:
url: git@github.com:open-runtime/runtime_isomorphic_library.git
tag_pattern: v{{version}}
version: ^1.2.6
version: ^3.0.0
grpc:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8
encrypt:
git:
url: git@github.com:open-runtime/encrypt.git
tag_pattern: v{{version}}
version: ^5.1.11
version: ^6.0.0

dev_dependencies:
# Resolves from workspace (packages/libraries/dart/runtime_ci_tooling) in monorepo.
Expand All @@ -51,7 +51,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
build_cli: ^2.2.10
build_runner: ^2.4.14
lints: ^6.0.0
Expand Down
3 changes: 2 additions & 1 deletion .consumers/runtime_common_codestyle/v0.1.10/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ homepage: https://github.com/open-runtime/runtime_common_codestyle
repository: https://github.com/open-runtime/runtime_common_codestyle
environment:
sdk: ^3.9.0

dependencies:
# ==========================================================================
#
Expand All @@ -21,4 +22,4 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
6 changes: 3 additions & 3 deletions .consumers/runtime_isomorphic_ipc/v0.1.2/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,12 +32,12 @@ dependencies:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8
runtime_isomorphic_library:
git:
url: git@github.com:open-runtime/runtime_isomorphic_library.git
tag_pattern: v{{version}}
version: ^1.2.6
version: ^3.0.0

dev_dependencies:
# ==========================================================================
Expand All @@ -52,7 +52,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This .consumers entry has a sibling metadata.json that records the pubspec SHA and discovered runtime_ci_tooling constraint. Since this PR updates the constraint here, the snapshot metadata will be stale unless the snapshot is regenerated (or metadata updated) as well.

Suggested change
version: ^0.14.1
version: ^0.14.0

Copilot uses AI. Check for mistakes.

# ==========================================================================
# Direct pub.dev dev dependencies
Expand Down
10 changes: 5 additions & 5 deletions .consumers/runtime_isomorphic_library/v1.2.5/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -29,10 +29,10 @@ dependencies:
http: ^1.3.0
googleapis: ^15.0.0
googleapis_auth: ^2.0.0
image: ^4.7.2
image: ^4.5.4
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency image downgraded instead of upgraded

Medium Severity

The image dependency minimum version was lowered from ^4.7.2 to ^4.5.4, which is the only downgrade in a PR where every other dependency change is an upgrade. This widens the constraint to allow versions 4.5.4–4.7.1 that were previously excluded, potentially losing important bug fixes (WebP decoder, EXIF injection, GIF transparency, TIFF decoding) introduced in versions 4.6.0–4.7.2. This looks like an accidental version digit swap or typo.

Fix in Cursor Fix in Web

moment_dart: ^5.3.0
protobuf: ^6.0.0
sentry: ^9.4.1
sentry: ^9.8.0
string_similarity: ^2.1.1

# ==========================================================================
Expand All @@ -44,20 +44,20 @@ dependencies:
git:
url: git@github.com:open-runtime/encrypt.git
tag_pattern: v{{version}}
version: ^5.1.11
version: ^6.0.0
grpc:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8

dev_dependencies:
analyzer: ">=8.0.0 <11.0.0"
runtime_ci_tooling:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These .consumers pubspecs look like generated release snapshots; the adjacent metadata.json stores the pubspec SHA and the discovered runtime_ci_tooling constraint. Changing the runtime_ci_tooling constraint here without regenerating/updating that metadata makes the snapshot internally inconsistent.

Suggested change
version: ^0.14.1

Copilot uses AI. Check for mistakes.
runtime_common_codestyle:
git:
url: git@github.com:open-runtime/runtime_common_codestyle.git
Expand Down
8 changes: 4 additions & 4 deletions .consumers/runtime_telemetric_library/v0.0.5/pubspec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ dependencies:
meta: ^1.16.0
protobuf: ^6.0.0
retry: ^3.1.2
sentry: ^9.4.1
sentry: ^9.8.0
synchronized: ^3.4.0

# ==========================================================================
Expand All @@ -34,12 +34,12 @@ dependencies:
git:
url: git@github.com:open-runtime/grpc-dart.git
tag_pattern: v{{version}}
version: ^5.3.7
version: ^5.3.8
runtime_isomorphic_library:
git:
url: git@github.com:open-runtime/runtime_isomorphic_library.git
tag_pattern: v{{version}}
version: ^1.2.6
version: ^3.0.0

dev_dependencies:
# ==========================================================================
Expand All @@ -54,7 +54,7 @@ dev_dependencies:
git:
url: git@github.com:open-runtime/runtime_ci_tooling.git
tag_pattern: v{{version}}
version: ^0.9.1
version: ^0.14.1

# ==========================================================================
# Direct pub.dev dev dependencies
Expand Down
Loading