Skip to content

chore(deps): bump tinybus and tinytools to main - #20

Merged
senamakel merged 2 commits into
mainfrom
deps-repin
Oct 9, 2026
Merged

senamakel merged 2 commits into
mainfrom
deps-repin

Conversation

@senamakel

@senamakel senamakel commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Moves vendor/tinybus from 65741c3 to tinybus main (356bb24) and tinytools to main (bd60b9b).

The tinybus commits in between are host-side (module admission control, the Windows ACL and macOS group-write checks, the bundle digest marker); the module-side API is unchanged. Part of a pass that brings every tinyhumansai module onto its dependencies' latest commits, then cuts releases and re-pins OpenHuman.

Verified locally: cargo check --workspace --all-features --all-targets.

Summary by CodeRabbit

  • Chores
    • Updated revisions of internal components. These updates do not include any changes to user-facing features or behavior. No new capabilities, interface changes, or workflow updates are part of this release.

senamakel and others added 2 commits October 9, 2026 20:02
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T17:14:44.369726Z f42fb1b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: cf4402d1-d1d9-4551-92c0-dee2ac592907

📥 Commits

Reviewing files that changed from the base of the PR and between 7913e1b and f42fb1b.


⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock

📒 Files selected for processing (2)
  • Cargo.toml
  • vendor/tinybus

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The optional tinytools Git dependency and the vendor/tinybus submodule now point to new revisions.

Changes

Dependency revision updates

Layer / File(s) Summary
Update dependency revisions
Cargo.toml, vendor/tinybus
Cargo.toml pins tinytools to revision bd60b9b52f1998b4483b9cf107a72d3338e672f8. The vendor/tinybus submodule reference points to commit 356bb24f30d7863d81569c7e1f07a7ae60feda48.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other


Merge Risk: ⚪ Minimal · up to f42fb

This is a dependency revision bump with no identified behavior regression. Normal build and test checks are sufficient before merging.

Architecture Summary

Architecture risk: 🔵 Low · up to f42fb

The change affects 1 system.

Changed systems: Cargo.toml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — Cargo.toml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in Cargo.toml: The optional tinytools Git dependency now uses revision bd60b9b52f1998b4483b9cf107a72d3338e672f8 instead of 8feb5571e52baa145b5c7c473b16cd59de2b103a.
  • observed — Modified behavior in vendor/tinybus: The vendor/tinybus submodule commit reference changed from 65741c3828f7e8e055abbfb5ca8ae688559e490a to 356bb24f30d7863d81569c7e1f07a7ae60feda48.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the dependency updates for tinybus and tinytools to their main revisions.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks the pins in place,
Then hops along at gentle pace.
Two revisions take their turn,
While clover waits for spring to return.
One soft thump, and all is done.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper

tinysweeper Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

This PR bumps the pinned `tinytools` Git dependency revision in `Cargo.toml` (from `8feb557` to `bd60b9b`). Review lanes found no correctness or security issues in the diff, and no behavioural change. One description-mismatch finding: the PR description claims a `vendor/tinybus` bump that is not present in the diff. Note that code retrieval and memory were unavailable to the reviewing lanes, so reviews ran on the diff alone.

State: Ready for maintainer review
Priority: medium
Reviewed head: f42fb1b0a6ca
Updated: 1791565993 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 0 Active findings 1
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

`Cargo.toml` updates the optional `tinytools` git dependency pinned revision from `8feb5571e52baa145b5c7c473b16cd59de2b103a` to `bd60b9b52f1998b4483b9cf107a72d3338e672f8` (Cargo.toml). The lane summaries indicate `Cargo.lock` is synchronized to the same revision, and that nothing outside documentation, configuration and tests changed behaviourally.

Features

  • Modified — Bump pinned tinytools git revision: The `tinytools` optional dependency now resolves to revision `bd60b9b52f1998b4483b9cf107a72d3338e672f8` instead of `8feb5571e52baa145b5c7c473b16cd59de2b103a`. Reviewers found no correctness or security problem with this pin update; the comment above the pin notes the intent that both checkouts resolve to one package so `tinytools::ToolResult` stays one type. (Cargo.toml, Cargo.toml#percent-encoding = { version = "2", optional = true })

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • medium · description · Description claims a tinybus vendor bump the diff does not contain — The pull request body says the change "Moves `vendor/tinybus` from 65741c3 to tinybus main (356bb24)", but the only change in the diff is the `tinytools` rev bump. Per the repo rul (\(pull request description\))

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The dependency revision update is consistent with the committed `Cargo.lock` entry and shows no correctness issue in the provided diff; the lane deemed it safe to merge.
  • Lane summary: The dependency revision update is consistent with the committed Cargo.lock entry and does not show a correctness issue in the provided diff. Safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: No security problem is evident in this dependency pin update; the change updates the pinned `tinytools` Git revision with `Cargo.lock` synchronized to the same revision, so the lane deemed it safe to merge.
  • Lane summary: The change updates the pinned `tinytools` Git revision, with `Cargo.lock` synchronized to the same revision. No security problem is evident in this dependency pin update, so it is safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Positive: Reviewers observed no behavioural change: the diff contains nothing outside documentation, configuration and tests.
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Positive: Nothing sensitive found in what this pull request commits.
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The body claims the PR moves `vendor/tinybus` from 65741c3 to 356bb24, but the diff contains only the `tinytools` revision bump in Cargo.toml — there is no change to the vendored tinybus gitlink. Either the vendor update was not committed to this branch or the description overstates the change. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: \(pull request description\) — Description claims a tinybus vendor bump the diff does not contain

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.000346
  • Tokens: 29661 input · 2119 output · 3928 cached · 0 embedding
Head State Pass summary
f42fb1b0a6ca ready for maintainer review 1 active finding(s), 0 resolved finding(s) (at 1791565993)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0003 · 29,661 in / 2,119 out · 3,928 cached (13%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0002 · 13,868 in / 530 out   · 2,022 cached (15%) · gpt-5.6-luna
security:    $0.0001 · 10,247 in / 623 out   · 1,778 cached (17%) · gpt-5.6-luna
description: $0.0000 · 3,581 in  / 348 out   · 64 cached (2%)     · glm-5.3-flash

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f42fb1b0a6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread vendor/tinybus
@@ -1 +1 @@
Subproject commit 65741c3828f7e8e055abbfb5ca8ae688559e490a
Subproject commit 356bb24f30d7863d81569c7e1f07a7ae60feda48

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Split the TinyBus gitlink bump into its own commit

This commit combines the vendor/tinybus gitlink update with the unrelated TinyTools revision and lockfile changes, although the repository explicitly requires TinyBus gitlink updates to be made in a separate commit. Keeping this bump isolated preserves independent review and rollback of the vendored runtime dependency.

AGENTS.md reference: AGENTS.md:L168-L171

Useful? React with 👍 / 👎.

@senamakel
senamakel merged commit 38b0858 into main Oct 9, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant