Skip to content

Upgrade Sourcemeta dependencies - #941

Merged
jviotti merged 2 commits into
mainfrom
new-deps-again
Sep 23, 2026
Merged

jviotti merged 2 commits into
mainfrom
new-deps-again

Conversation

@jviotti

@jviotti jviotti commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Signed-off-by: Juan Cruz Viotti jv@jviotti.com

Review in cubic

Signed-off-by: Juan Cruz Viotti <jv@jviotti.com>
Signed-off-by: Juan Cruz Viotti <jv@jviotti.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 60 files

Re-trigger cubic

@augmentcode

augmentcode Bot commented Sep 23, 2026

Copy link
Copy Markdown
🤖 Augment PR Summary

Summary: This PR upgrades the vendored Sourcemeta Core and Blaze dependencies.

Changes:

  • Moves JSON Schema bundling from Blaze into Core as schema_bundle with configurable options.
  • Replaces Blaze's bundle component with a standalone dependencies-reporting library.
  • Updates Blaze compiler, codegen, configuration, and alterschema callers to the Core bundler.
  • Extends JSON Schema conversion with dialect validation, dependency keyword migration, and modern URI normalization.
  • Adds Draft 3 canonicalization logic that removes identifiers after rewriting references.
  • Improves 2019-09-to-2020-12 recursive-anchor and vocabulary conversion behavior.
  • Enhances Core OpenAPI framing with location limits and discriminator mapping analysis.
  • Updates CMake component exports and dependency pins for the new library layout.

🤖 Was this summary useful? React with 👍 or 👎

@augmentcode augmentcode Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed. 1 suggestion posted.

Fix All in Augment

Comment augment review to trigger a new review at any time.

if (callback) {
auto location{to_weak_pointer(container)};
location.push_back(std::cref(key));
callback(identifier, location);

@augmentcode augmentcode Bot Sep 23, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[vendor/core/src/core/jsonschema/bundle.cc:90] The callback's WeakPointer is documented as a pointer into the bundled root, but its final token references the local key string instead; retaining the callback argument (or a copy of it) leaves a dangling reference when embed_schema returns. This makes the new callback API unsafe for clients that collect embedding locations.

Severity: medium

Fix This in Augment

🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.

@jviotti
jviotti merged commit ad91fc9 into main Sep 23, 2026
14 checks passed
@jviotti
jviotti deleted the new-deps-again branch September 23, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant