Skip to content

Add npm dependency cooldown - #914

Open
ww-oai wants to merge 1 commit into
mainfrom
oss-remediation/01-cooldowns
Open

Add npm dependency cooldown#914
ww-oai wants to merge 1 commit into
mainfrom
oss-remediation/01-cooldowns

Conversation

@ww-oai

@ww-oai ww-oai commented Aug 20, 2026

Copy link
Copy Markdown

Minor, just aligns any local dev flows with Dependabot's cooldown.

Delay npm package resolution for seven days, including transitive dependencies of the pinned Steady CLI invocation.

Delay npm package resolution for seven days, including transitive dependencies of the pinned Steady CLI invocation.
@ww-oai ww-oai self-assigned this Aug 20, 2026
@ww-oai
ww-oai requested a review from a team as a code owner August 20, 2026 15:55
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 20, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-20T15:57:03.385543Z 931135d PR opened
🔒 Security Review Completed 2026-08-20T15:57:50.038133Z 931135d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

237/237 SDK tests passed in 16.646s for Java SDK PR #914.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 217ms
tests/chat-completions-create.test.ts ✅ Passed 815ms
tests/chat-completions-stream.test.ts ✅ Passed 343ms
tests/files-content-binary.test.ts ✅ Passed 249ms
tests/files-create-multipart.test.ts ✅ Passed 412ms
tests/files-list-pagination.test.ts ✅ Passed 311ms
tests/initialize-config.test.ts ✅ Passed 147ms
tests/instance-isolation.test.ts ✅ Passed 245ms
tests/models-list.test.ts ✅ Passed 171ms
tests/responses-background-lifecycle.test.ts ✅ Passed 279ms
tests/responses-body-method-errors.test.ts ✅ Passed 455ms
tests/responses-cancel-timeout.test.ts ✅ Passed 220ms
tests/responses-cancel.test.ts ✅ Passed 455ms
tests/responses-compact-retries.test.ts ✅ Passed 329ms
tests/responses-compact.test.ts ✅ Passed 440ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 603ms
tests/responses-create-advanced.test.ts ✅ Passed 1.366s
tests/responses-create-disconnect.test.ts ✅ Passed 1.246s
tests/responses-create-errors.test.ts ✅ Passed 355ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 297ms
tests/responses-create-retries.test.ts ✅ Passed 404ms
tests/responses-create-stream-failures.test.ts ✅ Passed 220ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 232ms
tests/responses-create-stream-wire.test.ts ✅ Passed 6.161s
tests/responses-create-stream.test.ts ✅ Passed 147ms
tests/responses-create-terminal-states.test.ts ✅ Passed 352ms
tests/responses-create-timeout.test.ts ✅ Passed 214ms
tests/responses-create.test.ts ✅ Passed 847ms
tests/responses-delete.test.ts ✅ Passed 269ms
tests/responses-input-items-errors.test.ts ✅ Passed 300ms
tests/responses-input-items-list.test.ts ✅ Passed 305ms
tests/responses-input-items-options.test.ts ✅ Passed 192ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 247ms
tests/responses-input-tokens-count.test.ts ✅ Passed 455ms
tests/responses-malformed-inputs.test.ts ✅ Passed 5.024s
tests/responses-not-found-errors.test.ts ✅ Passed 333ms
tests/responses-parse.test.ts ✅ Passed 685ms
tests/responses-retrieve-retries.test.ts ✅ Passed 433ms
tests/responses-retrieve.test.ts ✅ Passed 348ms
tests/responses-stored-method-errors.test.ts ✅ Passed 1.028s
tests/retry-behavior.test.ts ✅ Passed 3.626s
tests/sdk-error-shape.test.ts ✅ Passed 435ms

View OkTest run #32389032880

SDK merge (5e3e8326f11e) · head (931135d071cc) · base (4615e4e53f50) · OkTest (2b1bdfd25e98)

@github-actions

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

61 mixed files remain; 0 existing customizations changed.

Compared 4615e4e53f50931135d071cc. Generated baselines verified.

61 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ImageServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/audio/TranscriptionServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/beta/ResponseServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/chat/ChatCompletionService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/finetuning/checkpoints/PermissionServiceImpl.kt
  • openai-java-core/src/test/kotlin/com/openai/models/beta/responses/BetaResponsesServerEventTest.kt
  • openai-java-core/src/test/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParamsTest.kt
  • openai-java-core/src/test/kotlin/com/openai/models/embeddings/EmbeddingTest.kt
  • openai-java-core/src/test/kotlin/com/openai/models/responses/ResponsesServerEventTest.kt

21 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 32389033138 --repo openai/openai-java \
  --name castiron-custom-code-32389033138-1 --dir /tmp/castiron-custom-code-32389033138-1
git apply --stat /tmp/castiron-custom-code-32389033138-1/custom-code.patch
cat /tmp/castiron-custom-code-32389033138-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 4615e4e53f50f3106ded091c97f9f51b7457116d 931135d071ccaef71f8100e222d9430bd973d985
python3 scripts/castiron/custom_code_report.py report \
  --base 4615e4e53f50f3106ded091c97f9f51b7457116d \
  --head 931135d071ccaef71f8100e222d9430bd973d985 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-931135d071cc
cat /tmp/castiron-custom-code-931135d071cc/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 931135d071

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .npmrc
@@ -0,0 +1 @@
min-release-age=7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a cooldown setting supported by npm

Whenever scripts/mock invokes npm exec, npm ignores this setting: with npm 11.4.2, npm config ls -l emits Unknown project config "min-release-age", and the npm v11 configuration reference documents no such option (its related before option accepts a fixed date). Consequently, the pinned Steady CLI's transitive dependencies are still resolved without the intended seven-day gate, so this change provides none of the stated supply-chain protection.

AGENTS.md reference: AGENTS.md:L24-L26

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant