Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/pr_code_changes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ jobs:
- uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Set up Python
uses: actions/setup-python@v6
with:
Expand All @@ -68,6 +70,8 @@ jobs:
allow-prereleases: true
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Install package (no country-model extras)
run: uv pip install --system .
- name: Smoke-import core modules
Expand All @@ -83,6 +87,8 @@ jobs:
- uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Set up Python
uses: actions/setup-python@v6
with:
Expand Down Expand Up @@ -131,6 +137,8 @@ jobs:
uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"

- name: Set up Python
uses: actions/setup-python@v6
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/pr_docs_changes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ jobs:
uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Set up Python
uses: actions/setup-python@v6
with:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ jobs:
uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Set up Python
uses: actions/setup-python@v6
with:
Expand Down Expand Up @@ -116,6 +118,8 @@ jobs:
run: git fetch --tags --force
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Setup Python
uses: actions/setup-python@v6
with:
Expand Down Expand Up @@ -166,6 +170,8 @@ jobs:
uses: actions/checkout@v6
- name: Install uv
uses: astral-sh/setup-uv@v8.1.0
with:
version: "0.12.14"
- name: Set up Python
uses: actions/setup-python@v6
with:
Expand Down
1 change: 1 addition & 0 deletions changelog.d/521.fixed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Pinned the uv release in every CI `setup-uv` step and regenerated the lock with it, so the Versioning lock refresh reproduces the reviewed dependency graph instead of failing on resolver-version marker rewrites.
5 changes: 4 additions & 1 deletion docs/release-bundles.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,10 @@ from PyPI without local sources, and permits only the root package version to ch
in the reviewed lock. Every locked distribution must use an HTTPS artifact URL
on PyPI's `files.pythonhosted.org` host and a valid SHA256 digest; a registry source
label alone is insufficient. Any dependency graph change fails and restores the original
lock; stage such changes in a reviewed PR instead. The helper then runs the actual
lock; stage such changes in a reviewed PR instead. Every workflow pins the uv release in its
`setup-uv` step: the lock's dependency-marker spelling depends on the resolver
version, so an unpinned latest uv can rewrite reviewed edges and fail this check.
Raise that pin and regenerate `uv.lock` with the same uv in one reviewed PR. The helper then runs the actual
`uv lock --check`. Final unpublished dependency pins must wait for registry
publication before these checks can pass.

Expand Down
4 changes: 2 additions & 2 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading