Skip to content

Update dependency promptfoo to v0.121.20 - #554

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/promptfoo-0.x-lockfile
Open

Update dependency promptfoo to v0.121.20#554
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/promptfoo-0.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
promptfoo (source) 0.121.180.121.20 age confidence

Release Notes

promptfoo/promptfoo (promptfoo)

v0.121.20

Compare Source

Features
Bug Fixes

v0.121.19

Compare Source

Features
Bug Fixes

Configuration

📅 Schedule: (in timezone Europe/London)

  • Branch creation
    • "before 10am on friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Renovatebot and dependabot updates frontend javascript Pull requests that update javascript code labels Jul 24, 2026
@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown

Caution

[High Risk] Replacing the only healthy ALB backend will cause temporary API downtime

The change replaces the EC2 instance behind 540044833068.eu-west-2.elbv2-target-group.api-207c90ee-tg and also replaces its aws_lb_target_group_attachment. In the current state, that target group has only one registered backend, i-0bf4039822e01f430, and it is the sole healthy target serving the ALB on port 80 with HTTP /health checks.

During apply, the old instance will be deregistered or drained while the replacement instance is created, attached, registered, and waits to pass its initial health checks. Because there is no second healthy target in the group to absorb traffic, the ALB will temporarily have zero healthy backends and requests to the API service will fail until the new instance becomes healthy.
View reasoning tree here.

Caution

[High Risk] Instance-specific alert retargeting will create a monitoring gap during compute replacement

The change replaces the AWS API server instance and both GCP service instances while the corresponding CloudWatch and Cloud Monitoring alerts are scoped to ephemeral instance identifiers. The current CloudWatch alarm targets only InstanceId=i-0bf4039822e01f430, and the GCP alert policies filter on exact resource.labels.instance_id values for inventory-api and payments-api. Because replacement creates new instance IDs, the monitoring configuration is being retargeted at the same time as the compute cutover instead of using stable labels or overlapping coverage.

During the replacement window, CPU and uptime alerts can stop matching either the old or new instances, leaving outages or failed startups undetected across both AWS and GCP. The new SNS email subscription also will not deliver notifications until the recipient confirms the subscription, so even alerts that do fire may not reach responders.
View reasoning tree here.

Signals

Routine → Multiple compute and monitoring resources are showing unusual, infrequent update patterns that may need review, most commonly at 1 event/week for the last 2-5 months. Some API server and subscription resources changed slightly more often at 2-4 events/week for the last 3-5 months.

Additional Change Details: Items 72 Edges 137 model|risks_v6 ✨Encryption Key State Risk ✨KMS Key Creation

View in Overmind

@renovate
renovate Bot force-pushed the renovate/promptfoo-0.x-lockfile branch from e9874ae to 928b4f4 Compare July 31, 2026 06:10
@renovate renovate Bot changed the title Update dependency promptfoo to v0.121.19 Update dependency promptfoo to v0.121.20 Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Renovatebot and dependabot updates frontend javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants