Repository navigation
Relock pytest that dependabot downgraded, drop tox from the dev group - #776
Open
RonnyPfannschmidt wants to merge 2 commits into
Open
RonnyPfannschmidt wants to merge 2 commits into
RonnyPfannschmidt wants to merge 2 commits into
Conversation
Dependabot's uv updater relocks without git and pretends the project version through SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PLUGGY, using the setuptools-scm fallback_version or "0.0.0" when there is none. As pluggy 0.0.0, no current pytest (pluggy>=1.5,<2) or tox (pluggy>=1.6) is installable, so 6f8fa68 silently resolved pytest 3.2.5, pytest-benchmark 3.1.1 and tox 1.9.2. pytest 3.2.5 imports `imp` and cannot start on Python 3.12+, so `uv run pytest` fails on main. Set fallback_version to 1.6.0+fallback, which satisfies both consumers; the local label marks it as fake and PyPI refuses local versions. Floor pytest>=8 and tox>=4 so a future bogus version fails the relock instead of downgrading. Relock pytest, pytest-benchmark and tox. Co-Authored-By: Claude Opus 5.5 via Claude Code <noreply@anthropic.com>
Nothing uses the tox installed into the project environment: CI installs its own, the downstream runner builds its own venvs, and releasing only needs a tox on PATH. Installed there it runs on the editable pluggy under test, and its pluggy>=1.6 requirement was the second dependency that a bogus dependabot version downgraded. Document uv as the development setup, with tox run as a tool via uvx; the old `pip install -e .[dev]` named an extra that does not exist. Reword the fallback_version comment to say it only serves dependabot. Co-Authored-By: Claude Opus 5.5 via Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Written by Claude Opus 5.5 via Claude Code for the pluggy maintainers; I prompted it, it did the work, I read it.
#756 (virtualenv bump) also downgraded pytest 9.0.3 → 3.2.5, pytest-benchmark 5.2.3 → 3.1.1 and tox 4.53 → 1.9.2 in
uv.lock. pytest 3.2.5 importsimp, souv run pytestno longer starts on Python 3.12+. CI is unaffected because tox installs its own dependencies.Cause: dependabot relocks from files fetched through the API, without git, and pretends the project version via
SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PLUGGY:[tool.setuptools_scm] fallback_version, else"0.0.0"(dependabot/dependabot-core#13945). As pluggy 0.0.0, no current pytest (pluggy>=1.5) or tox (pluggy>=1.6) can be installed, so the resolver silently picked releases that predate the dependency.Changes:
fallback_version = "1.6.0+fallback". It is a workaround for dependabot, not a real version; the local label keeps it off PyPI.pytest>=8floor, so a bogus version makes the relock fail instead of downgrading.devgroup. Nothing used that copy: CI installs its own, the downstream runner builds its own venvs, and releasing only needs a tox on PATH. Installed in the project environment, it runs on the editable pluggy under test.uvx toxfor the matrix;RELEASING.rstusesuvx tox -e release. The oldpip install -e .[dev]named an extra that doesn't exist.Checked:
--upgrade-package virtualenv) keeps pytest 9.1.1.0.0.0the relock fails as unsatisfiable.1.6.0+fallback.uvx tox -e docspasses.