From 234db6b262919174c351a4e864ee7c0df79ce555 Mon Sep 17 00:00:00 2001 From: Max Ghenis Date: Tue, 15 Sep 2026 07:59:43 -0400 Subject: [PATCH] Pin the CI uv release and regenerate the lock with it The 6.0.0 Versioning job failed at release_lock.py --refresh: setup-uv installed the latest uv (0.12.14), which rewrites two dependency-edge markers in uv.lock on a cold cache, so the post-bump lock differed from the reviewed lock beyond the root version and the refresh failed closed. uv lock --check accepts both spellings, which is why PR checks passed. Pin uv 0.12.14 in every setup-uv step and regenerate uv.lock with that release, so the refresh changes only the root version. Reproduced locally: 0.11.7 keeps the markers, 0.12.14 drops them and is idempotent afterwards; the simulated bump + generate + refresh now passes with a root-only diff. Fixes #521 Co-Authored-By: Claude Fable 5.1 --- .github/workflows/pr_code_changes.yaml | 8 ++++++++ .github/workflows/pr_docs_changes.yaml | 2 ++ .github/workflows/push.yaml | 6 ++++++ changelog.d/521.fixed.md | 1 + docs/release-bundles.md | 5 ++++- uv.lock | 4 ++-- 6 files changed, 23 insertions(+), 3 deletions(-) create mode 100644 changelog.d/521.fixed.md diff --git a/.github/workflows/pr_code_changes.yaml b/.github/workflows/pr_code_changes.yaml index d64d5424..978c13cb 100644 --- a/.github/workflows/pr_code_changes.yaml +++ b/.github/workflows/pr_code_changes.yaml @@ -44,6 +44,8 @@ jobs: - uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 with: @@ -68,6 +70,8 @@ jobs: allow-prereleases: true - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Install package (no country-model extras) run: uv pip install --system . - name: Smoke-import core modules @@ -83,6 +87,8 @@ jobs: - uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 with: @@ -131,6 +137,8 @@ jobs: uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 diff --git a/.github/workflows/pr_docs_changes.yaml b/.github/workflows/pr_docs_changes.yaml index 7668bca4..9e70a97a 100644 --- a/.github/workflows/pr_docs_changes.yaml +++ b/.github/workflows/pr_docs_changes.yaml @@ -20,6 +20,8 @@ jobs: uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 with: diff --git a/.github/workflows/push.yaml b/.github/workflows/push.yaml index fa367e7b..c12509a2 100644 --- a/.github/workflows/push.yaml +++ b/.github/workflows/push.yaml @@ -49,6 +49,8 @@ jobs: uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 with: @@ -116,6 +118,8 @@ jobs: run: git fetch --tags --force - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Setup Python uses: actions/setup-python@v6 with: @@ -166,6 +170,8 @@ jobs: uses: actions/checkout@v6 - name: Install uv uses: astral-sh/setup-uv@v8.1.0 + with: + version: "0.12.14" - name: Set up Python uses: actions/setup-python@v6 with: diff --git a/changelog.d/521.fixed.md b/changelog.d/521.fixed.md new file mode 100644 index 00000000..e3a648c9 --- /dev/null +++ b/changelog.d/521.fixed.md @@ -0,0 +1 @@ +Pinned the uv release in every CI `setup-uv` step and regenerated the lock with it, so the Versioning lock refresh reproduces the reviewed dependency graph instead of failing on resolver-version marker rewrites. diff --git a/docs/release-bundles.md b/docs/release-bundles.md index 63026246..393c7a97 100644 --- a/docs/release-bundles.md +++ b/docs/release-bundles.md @@ -51,7 +51,10 @@ from PyPI without local sources, and permits only the root package version to ch in the reviewed lock. Every locked distribution must use an HTTPS artifact URL on PyPI's `files.pythonhosted.org` host and a valid SHA256 digest; a registry source label alone is insufficient. Any dependency graph change fails and restores the original -lock; stage such changes in a reviewed PR instead. The helper then runs the actual +lock; stage such changes in a reviewed PR instead. Every workflow pins the uv release in its +`setup-uv` step: the lock's dependency-marker spelling depends on the resolver +version, so an unpinned latest uv can rewrite reviewed edges and fail this check. +Raise that pin and regenerate `uv.lock` with the same uv in one reviewed PR. The helper then runs the actual `uv lock --check`. Final unpublished dependency pins must wait for registry publication before these checks can pass. diff --git a/uv.lock b/uv.lock index 279fc5e0..37b86de6 100644 --- a/uv.lock +++ b/uv.lock @@ -197,7 +197,7 @@ name = "cffi" version = "2.0.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "pycparser", marker = "implementation_name != 'PyPy'" }, + { name = "pycparser" }, ] sdist = { url = "https://files.pythonhosted.org/packages/eb/56/b1ba7935a17738ae8453301356628e8147c79dbb825bcbc73dc7401f9846/cffi-2.0.0.tar.gz", hash = "sha256:44d1b5909021139fe36001ae048dbdde8214afa20200eda0f64c068cac5d5529", size = 523588, upload-time = "2025-09-08T23:24:04.541Z" } wheels = [ @@ -1679,7 +1679,7 @@ name = "pexpect" version = "4.9.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "ptyprocess", marker = "sys_platform != 'emscripten' and sys_platform != 'win32'" }, + { name = "ptyprocess" }, ] sdist = { url = "https://files.pythonhosted.org/packages/42/92/cc564bf6381ff43ce1f4d06852fc19a2f11d180f23dc32d9588bee2f149d/pexpect-4.9.0.tar.gz", hash = "sha256:ee7d41123f3c9911050ea2c2dac107568dc43b2d3b0c7557a33212c398ead30f", size = 166450, upload-time = "2023-11-25T09:07:26.339Z" } wheels = [