Fix bug-test Python dependency provisioning - #4030
Conversation
There was a problem hiding this comment.
Pull request overview
Fixes the bug-test workflow’s Python test environment provisioning.
Changes:
- Provisions Python 3.14, uv, and test dependencies.
- Allows PyPI traffic through the workflow firewall.
- Adds static source and compiled-workflow coverage.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/bug-test.md |
Configures Python tooling and PyPI access. |
.github/workflows/bug-test.lock.yml |
Compiles the updated workflow configuration. |
tests/test_github_workflows.py |
Verifies provisioning, firewall domains, pins, and step order. |
Review details
Tip
Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 3/3 changed files
- Comments generated: 0
- Review effort level: Balanced
Address CodeQL py/incomplete-url-substring-sanitization alerts (14-17) by anchoring the PyPI domain assertions to their structural context: the `network.allowed` YAML list items in the source and the quoted JSON entries in the compiled lock. This defeats the incomplete-URL-substring pattern and strengthens the test to confirm the domains are real allowlist entries rather than incidental substrings. Assisted-by: GitHub Copilot (model: Claude Opus 4.8, supervised) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7b54442f-ccc5-4be1-a05c-b360889670e5
Replace `uv sync --extra test` with `uv pip install --system -e ".[test]"` in the bug-test provisioning step. `uv sync` writes a root `uv.lock` (and `.venv`) into the working tree. This repository intentionally has no `uv.lock`/`[tool.uv]` (uv.lock is gitignored), so the sync produced an untracked lockfile before the agent checks out the fix ref in Step 2. `uv pip install` installs the test extra into the runner's Python without generating a project lock, keeping the working tree clean before the fix checkout. The editable install means the agent's `python3 -m pytest` runs against the checked-out fix code. Recompiled the lock and updated the assertions accordingly. Assisted-by: GitHub Copilot (model: Claude Opus 4.8, supervised) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7b54442f-ccc5-4be1-a05c-b360889670e5
… workflows Dependabot bumps the third-party action `uses:` pins (and header comments) directly, but does not update gh-aw's own metadata: the per-file `gh-aw-manifest` JSON blob and the shared `.github/aw/actions-lock.json` pin cache. As a result the executing pins were already uniform and current (checkout v7.0.1, setup-node v7.0.0) while the manifest/cache metadata still recorded checkout v6.0.3 / setup-node v6.4.0. This is a latent downgrade hazard: a plain `gh aw compile` reads the stale cache and can silently revert the `uses:` lines back to the older pins, undoing Dependabot's bumps and breaking lockstep. Sync all four pin surfaces (uses / header comment / manifest / cache) to the current pins so every workflow agrees and a future recompile is a no-op: - actions-lock.json: checkout v6.0.3 -> v7.0.1, setup-node v6.4.0 -> v7.0.0, and add the setup-python v7.0.0 + setup-uv v9.0.0 entries now used by bug-test. - gh-aw-manifest blobs in the 5 non-bug-test lock files: checkout + setup-node bumped to match their own uses lines (bug-test was already current). No workflow body changes; only pin metadata. `uses:` pins are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7b54442f-ccc5-4be1-a05c-b360889670e5 Assisted-by: GitHub Copilot (model: Claude Opus 4.8, supervised)
|
Pushed Why: Dependabot already keeps the executing Change (metadata only, no workflow-body changes,
Verified: no stale SHAs remain; all 6 manifests uniform at latest; Posted on behalf of @mnriem by GitHub Copilot (model: Claude Opus 4.8). This commit was agent-generated under maintainer supervision. |
|
Thank you! |
Closes #3997.
Summary
bug-testagent runs.uv sync --extra test.Validation
PYTHONDONTWRITEBYTECODE=1 .venv/bin/python -m pytest -p no:cacheprovider tests/test_github_workflows.py -qPYTHONDONTWRITEBYTECODE=1 .venv/bin/python -m pytest -p no:cacheprovider tests/test_security_workflow.py::TestDependencyAuditWorkflow::test_setup_python_pin_matches_repo_standard tests/test_security_workflow.py::TestDependencyAuditWorkflow::test_setup_uv_pin_matches_repo_standard -quvx ruff@0.15.0 check tests/test_github_workflows.pygit diff --check/tmp/gh-aw-0.79.8.sGWKqX/linux-amd64 compile bug-test --no-emit --approve