ci: generate locks from pyproject, guard course pins, harden Validate - #99
Merged
Merged
Conversation
- Lock files are now produced by `make lock` (uv pip compile --universal from the 3.11 floor) instead of by hand; every existing pin is kept, and the Windows-only colorama and <3.13 typing-extensions pins the manual lock missed are added. A new `lock` job runs `make lock-check`, which re-resolves copies of the committed locks and fails on any diff. - tests/test_dependency_pins.py requires course/path requirements.txt pins to equal the CI lock, so CI tests the stack learners install. - Validate adds Python 3.14, sets fail-fast: false, SHA-pins actions, moves setup-uv v7 -> v10.2.0, and pins uv 0.12.19. - Remove notify-site.yml: WEBSITE_SYNC_TOKEN was never set, so all 32 runs skipped the dispatch while reporting success, and the website builds from its own pin anyway. - Remove mypy, its type stubs, and [tool.mypy]: never locked or run. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
make lockrunsuv pip compile --universalfrom the Python 3.11 floor, so per-Python splits (numpy/contourpy on 3.11) are handled automatically. All existing pins kept; adds the Windows-onlycoloramaand Python <3.13typing-extensionspins the manual lock had missed. Newlockjob runsmake lock-check: it re-resolves copies of the committed locks (uv keeps every pin that still satisfiespyproject.toml) and fails on any diff. In-place pin bumps such as Dependabot's still pass.tests/test_dependency_pins.pyfails if a course/pathrequirements.txtpin differs fromrequirements-dev.lock.txt, so CI can't pass on a stack learners never get (the PR chore(deps): bump the python-dependencies group across 1 directory with 13 updates #94 pandas 3 risk).fail-fast: false, SHA-pinned actions,setup-uvv7 → v10.2.0 (the breaking changes don't affect us: cache is enabled explicitly, no custom manifest), uv pinned to 0.12.19.notify-site.yml.WEBSITE_SYNC_TOKENwas never configured: 32/32 runs skipped the dispatch step while showing success. The website builds from its own content pin, so a dispatch would only re-verify old content.[tool.mypy]. The lock never installed them and CI never ran them.Test plan
make checkpasses on clean Python 3.11 and 3.14 venvs from the new lock (139 tests)make lock-checkpasses with the current locks and with an in-place pin bump; fails whenpyproject.tomlgains an unlocked dependencymake lock-checkoutput is identical under uv 0.12.19 (CI) and 0.12.21 (local)pandas==3.0.6pip install -r requirements-dev.lock.txt+pip checksucceedlock+validate3.11/3.12/3.13/3.14 greenGenerated with Devin