Skip to content

Pin the CI uv release and regenerate the lock with it - #522

Merged
MaxGhenis merged 1 commit into
mainfrom
fix/pin-release-resolver-uv
Sep 15, 2026
Merged

MaxGhenis merged 1 commit into
mainfrom
fix/pin-release-resolver-uv

Conversation

@MaxGhenis

Copy link
Copy Markdown
Contributor

Fixes #521

The 6.0.0 Versioning job (run 34962073254) failed at python scripts/release_lock.py --refresh with "Versioning changed the reviewed dependency graph". setup-uv@v8.1.0 installs the latest uv (0.12.14, released 2026-09-14). On a cold cache that release rewrites two dependency-edge markers in uv.lock (cffi -> pycparser, pexpect -> ptyprocess), so the post-bump lock differed from the reviewed lock beyond the root version and the strict refresh failed closed. uv lock --check accepts either spelling, which is why the PR checks on #515 passed.

This pins uv 0.12.14 in every setup-uv step (push, PR code, PR docs workflows), regenerates uv.lock with that release (the only change is the two marker lines; every version, URL and hash is unchanged), and documents the pin in docs/release-bundles.md.

Validation (local, uv 0.12.14 on PATH):

  • python scripts/release_lock.py passes on the regenerated lock at 5.3.1.
  • Simulated Versioning: bump_version.py + scripts/bundle.py generate + release_lock.py --refresh passes; the lock diff is the root version only (5.3.1 -> 6.0.0). Bump reverted before commit.
  • uv lock --refresh with 0.12.14 on the regenerated lock is a no-op (idempotent); with 0.11.7 the markers reappear, which is what the pin prevents.
  • make lint passes.

Merging this to main triggers the push workflow, whose Versioning job consumes the pending 6.0.0 fragments from #515 and this one.

🤖 Generated with Claude Code

The 6.0.0 Versioning job failed at release_lock.py --refresh: setup-uv
installed the latest uv (0.12.14), which rewrites two dependency-edge
markers in uv.lock on a cold cache, so the post-bump lock differed from
the reviewed lock beyond the root version and the refresh failed closed.
uv lock --check accepts both spellings, which is why PR checks passed.

Pin uv 0.12.14 in every setup-uv step and regenerate uv.lock with that
release, so the refresh changes only the root version. Reproduced locally:
0.11.7 keeps the markers, 0.12.14 drops them and is idempotent afterwards;
the simulated bump + generate + refresh now passes with a root-only diff.

Fixes #521

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@MaxGhenis
MaxGhenis marked this pull request as ready for review September 15, 2026 12:33
@MaxGhenis
MaxGhenis merged commit bff6764 into main Sep 15, 2026
24 of 25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Versioning lock refresh fails under an unpinned uv release

1 participant