Skip to content

Further adoption of uv in ci - #1056

Draft
mdellweg wants to merge 2 commits into
pulp:mainfrom
mdellweg:uv_adoption
Draft

mdellweg wants to merge 2 commits into
pulp:mainfrom
mdellweg:uv_adoption

Conversation

@mdellweg

Copy link
Copy Markdown
Member

📜 Checklist

  • Commits are cleanly separated with meaningful messages (simple features and bug fixes should be squashed to one commit)
  • A changelog entry or entries has been added for any significant changes
  • Follows the Pulp policy on AI Usage
  • (For new features) - User documentation and test coverage has been added

See: Pull Request Walkthrough

Each workflow can and should set their permissions on the GITHUB_TOKEN
as necessary.

@pedro-psb pedro-psb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think of adding the cool-off period, since uvx are unconstrained calls?
Something like the following for a job:

      - name: Set UV cool-off period
        run: |
          COOL_OFF_DATE=$(date -d "2 weeks ago" +%Y-%m-%d)
          echo "UV_EXCLUDE_NEWER=$COOL_OFF_DATE" >> $GITHUB_ENV

@mdellweg

Copy link
Copy Markdown
Member Author

What do you think of adding the cool-off period, since uvx are unconstrained calls? Something like the following for a job:

      - name: Set UV cool-off period
        run: |
          COOL_OFF_DATE=$(date -d "2 weeks ago" +%Y-%m-%d)
          echo "UV_EXCLUDE_NEWER=$COOL_OFF_DATE" >> $GITHUB_ENV

I'm not so sure what exact problem that will solve. I think we can however add development dependencies to pyproject.toml and change all "uvx" calls to "uv run". This way we can use version specifiers.

@mdellweg
mdellweg marked this pull request as draft September 25, 2026 12:57
@pedro-psb

Copy link
Copy Markdown
Member

These tools run in jobs with priviledged access. This reduces the chance of us getting a compromised package right after it's released.

But yeah, specifying explicitly in pyproject.toml sounds an improvement (in this case, better control/stability).
It even makes me think of a lockfile for the CI runner dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants