Skip to content

Fix platformdirs pytest startup and packaging dependency advisories - #438

Merged
ibrahim halatci (ihalatci) merged 3 commits into
developfrom
ihalatci-platformdirs-dependency-fix
Oct 6, 2026
Merged

ibrahim halatci (ihalatci) merged 3 commits into
developfrom
ihalatci-platformdirs-dependency-fix

Conversation

@ihalatci

@ihalatci ibrahim halatci (ihalatci) commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Fix pytest startup with platformdirs==4.12.1, the first plugin release containing the startup-import correction. Document Python >=3.10.

Apply reviewed security floors with focused Python 3.10 lock regeneration:

Package Final lock Evidence
GitPython 3.1.62 GHSA-59cr-6r3x-644w; also covers earlier RCE advisories
PyJWT[crypto] 2.15.0 GHSA-42vr-xj54-vc7v; also covers key-confusion advisories
urllib3 2.8.0 GHSA-8988-9cw3-xx77 and chunked-stream fixes
AnyIO 4.14.2 GHSA-82r6-8w77-94w6
setuptools 83.0.0 GHSA-h35f-9h28-mq5c, plus earlier PackageIndex arbitrary-write fix
wheel 0.48.0 Upstream converter traversal fix in release notes; referenced GHSA-vgq5-9859-3mmw is not publicly retrievable
Click 8.3.3 Upstream shell-execution hardening; CVE-2026-7246 is explicitly disputed by Pallets, not a confirmed repository exploit

Setuptools now appears as an actual installed lock entry via pip-compile --allow-unsafe, rather than being omitted as unsafe. This controls the requirements installation, not every isolated third-party build environment.

Required tooling compatibility

Setuptools 83 removed pkg_resources, breaking Prospector 1.10.3 startup. The minimum resolvable compatible set is Prospector 1.12.1, pylint 3.0.0, astroid 3.0.0, pylint-django 2.6.1, pylint-plugin-utils 0.8, and requirements-detector 1.3.1. Prospector 1.12.0 has incompatible plugin constraints. Remove now-unused lazy-object-proxy; other dependency versions remain unchanged, including SQLAlchemy and python-dotenv.

Pylint 3 surfaced the release validator's conditional global dependency. Pass argparse.Namespace explicitly (two production lines), preserving CLI behavior; add eight offline validation cases and run them in Tool Tests. No lint suppressions or unrelated code changes.

Local validation

Isolated WSL Python 3.10:

  • Focused generated lock matches committed output; full installation and pip check pass, including actual setuptools 83.
  • Exact python -m prospector with unchanged repository config: zero messages.
  • Exact black . --check: all 40 files unchanged.
  • Eight validator cases plus 67 packaging warning-handler tests pass.
  • Pytest11 plugin/module and fixture pass; controlled old-module/new-metadata mismatch reproduces the original error, and corrected module loads.
  • 82 packaging build/helper/warning tests collect, including hosted test_build_packages.

Hosted rollout

Platformdirs-only tag v0.8.41-dev is preserved at 5dd0c746610f21fe6e01fc95048ebf0df7c39617. Packaging commit 4f3c66ccab893c70eea2a2e6607b629d7de644c1 passed 22/22 matrix jobs and packaging test steps in each workflow: Image Health Check, Build Package, Build package for test images. All 22 image push steps succeeded. Intermediate v0.8.41-security-dev also remains unchanged.

Final candidate: v0.8.41-final-dev at 5f62ab5959e5fb75a9538e7f25787dd294fa174a. Final hosted tools and repeated packaging validation pending. Review requests deferred until final tools checks are green. No merge or stable release authorized. Exact ambient metadata origin on the original failing runner remains unconfirmed.

Related: citusdata/packaging#1241, citusdata/packaging#1240.

Use 4.12.1, the first plugin release with the startup-import fix, and retain all other lock versions. Align the documented Python minimum with the installed dependencies.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
Lock GitPython 3.1.62, PyJWT 2.15.0, urllib3 2.8.0 and AnyIO 4.14.2 with source minimum constraints. Preserve all other locked versions and the validated platformdirs pin.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
@ihalatci ibrahim halatci (ihalatci) changed the title Pin platformdirs to fix pytest plugin startup in packaging Fix platformdirs pytest startup and packaging dependency advisories Oct 5, 2026
Install setuptools 83 via an allow-unsafe lock, update wheel and Click, and use the minimum resolvable Prospector compatibility set. Pass the release validator namespace explicitly and cover its validation paths offline in CI.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
@ihalatci

Copy link
Copy Markdown
Contributor Author

failed tests are due to change in getting package dependencies which will be addressed by citusdata/packaging#1242 not blocking this

@ihalatci
ibrahim halatci (ihalatci) merged commit b55decf into develop Oct 6, 2026
49 of 55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants