Repository navigation
Fix platformdirs pytest startup and packaging dependency advisories - #438
Merged
ibrahim halatci (ihalatci) merged 3 commits intoOct 6, 2026
Merged
Conversation
Use 4.12.1, the first plugin release with the startup-import fix, and retain all other lock versions. Align the documented Python minimum with the installed dependencies. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
Lock GitPython 3.1.62, PyJWT 2.15.0, urllib3 2.8.0 and AnyIO 4.14.2 with source minimum constraints. Preserve all other locked versions and the validated platformdirs pin. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
Install setuptools 83 via an allow-unsafe lock, update wheel and Click, and use the minimum resolvable Prospector compatibility set. Pass the release validator namespace explicitly and cover its validation paths offline in CI. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 16db2b29-47c2-4bf8-992e-ed325051912e
ibrahim halatci (ihalatci)
requested review from
Onur Tirtir (onurctirtir) and
serhat andic (serhatandic)
October 5, 2026 15:38
serhat andic (serhatandic)
approved these changes
Oct 6, 2026
Contributor
Author
|
failed tests are due to change in getting package dependencies which will be addressed by citusdata/packaging#1242 not blocking this |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Fix pytest startup with
platformdirs==4.12.1, the first plugin release containing the startup-import correction. Document Python >=3.10.Apply reviewed security floors with focused Python 3.10 lock regeneration:
Setuptools now appears as an actual installed lock entry via
pip-compile --allow-unsafe, rather than being omitted as unsafe. This controls the requirements installation, not every isolated third-party build environment.Required tooling compatibility
Setuptools 83 removed
pkg_resources, breaking Prospector 1.10.3 startup. The minimum resolvable compatible set is Prospector 1.12.1, pylint 3.0.0, astroid 3.0.0, pylint-django 2.6.1, pylint-plugin-utils 0.8, and requirements-detector 1.3.1. Prospector 1.12.0 has incompatible plugin constraints. Remove now-unused lazy-object-proxy; other dependency versions remain unchanged, including SQLAlchemy and python-dotenv.Pylint 3 surfaced the release validator's conditional global dependency. Pass
argparse.Namespaceexplicitly (two production lines), preserving CLI behavior; add eight offline validation cases and run them in Tool Tests. No lint suppressions or unrelated code changes.Local validation
Isolated WSL Python 3.10:
pip checkpass, including actual setuptools 83.python -m prospectorwith unchanged repository config: zero messages.black . --check: all 40 files unchanged.test_build_packages.Hosted rollout
Platformdirs-only tag
v0.8.41-devis preserved at5dd0c746610f21fe6e01fc95048ebf0df7c39617. Packaging commit4f3c66ccab893c70eea2a2e6607b629d7de644c1passed 22/22 matrix jobs and packaging test steps in each workflow: Image Health Check, Build Package, Build package for test images. All 22 image push steps succeeded. Intermediatev0.8.41-security-devalso remains unchanged.Final candidate:
v0.8.41-final-devat5f62ab5959e5fb75a9538e7f25787dd294fa174a. Final hosted tools and repeated packaging validation pending. Review requests deferred until final tools checks are green. No merge or stable release authorized. Exact ambient metadata origin on the original failing runner remains unconfirmed.Related: citusdata/packaging#1241, citusdata/packaging#1240.