From 4904021c677b4862448c2e01aa4f7448e2063d62 Mon Sep 17 00:00:00 2001 From: Carter Francis Date: Wed, 23 Sep 2026 21:17:48 -0500 Subject: [PATCH] =?UTF-8?q?ci(prepare-release):=20drop=20the=20uv.lock=20p?= =?UTF-8?q?re-flight=20=E2=80=94=20this=20repo=20has=20no=20lockfile?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The first real run of Prepare Release died at step 6: error: Unable to find lockfile at `uv.lock`, but `--check` was provided. uv.lock is on line 11 of .gitignore and has never been tracked. The step came straight from SpyDE's Prepare Release, and it was checked against a working tree where `uv sync` had left a lockfile lying around rather than against what git actually carries. It does not belong here either way. SpyDE is an APPLICATION: it ships its lock in the installer payload and the user's sidecar env is resolved from it, so drift reaches users. de-shell is a LIBRARY on PyPI — the apps resolve their own environments, and a lockfile here would mean nothing to them. The comment justifying the step described SpyDE's lock, which SpyDE already checks. The other pre-flight stays: the git-deps-pinned grep reads pyproject.toml and needs no lockfile. Also corrects two things the PR body claimed: - it said the lock check had passed; - it told the reviewer to confirm CI passes, but CI does not start on its own for a PR opened with GITHUB_TOKEN — GitHub suppresses workflow runs for events raised with it. The checklist now says so and how to get a run. Dry-run in a pristine clone of main with no .venv and no lockfile: compute version, git-deps check, bump + read-back, towncrier draft and build (which needs no de_shell import when --version is passed), and the release commit — all pass. 3 fragments consumed, CHANGELOG.rst assembled correctly. --- .github/workflows/prepare_release.yml | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/.github/workflows/prepare_release.yml b/.github/workflows/prepare_release.yml index f4066ba..d5e6053 100644 --- a/.github/workflows/prepare_release.yml +++ b/.github/workflows/prepare_release.yml @@ -149,15 +149,15 @@ jobs: fi # ── Release pre-flight checks — fail HERE, not at release time ─────── - # A drifted lock is the APPS' problem, not ours: they resolve the sidecar - # env from a lock on the user's machine, so it surfaces at their user's - # first launch rather than in any build of ours. - - name: Verify uv.lock is in sync with pyproject.toml - run: uv lock --check - + # No `uv lock --check` here, though SpyDE's Prepare Release has one: + # de-shell is a LIBRARY and .gitignore keeps uv.lock out of the repo, so + # the check can only ever fail. The lock that matters to a user is the + # app's — SpyDE ships its own in the installer payload and resolves the + # sidecar env from it on the user's machine — and SpyDE already checks it. + # # Git deps must reference explicit SHAs or tags, never moving branches — # otherwise the same release resolves different code over time. There are - # none today; this keeps it that way. + # none today; this keeps it that way. Needs no lockfile. - name: Verify git dependencies are pinned to SHAs or tags run: | bad=$(grep -nE "git\+https" pyproject.toml | grep -vE '@[0-9a-f]{40}"|@v?[0-9]+(\.[0-9]+)+[^"]*"' || true) @@ -242,7 +242,7 @@ jobs: ### What changed - \`de_shell/__init__.py\` bumped to \`${TAG#v}\` — the one place the version is written, and the value \`publish.yml\` refuses to let a tag disagree with - - Pre-flight checks passed: \`uv lock --check\`, git deps pinned to SHAs/tags + - Pre-flight checks passed: git dependencies pinned to SHAs or tags - \`CHANGELOG.rst\` assembled from the fragments in \`upcoming_changes/\`
Release notes (as they will appear in \`CHANGELOG.rst\`) @@ -255,8 +255,12 @@ jobs: ### Review checklist - [ ] \`CHANGELOG.rst\` reads well — edit the assembled text directly if needed - [ ] Version is correct in \`de_shell/__init__.py\` - - [ ] CI passes. The wheel-contents leg is the one that matters most: it fails - if \`de_shell/js\` is missing, which is the whole point of the package. + - [ ] CI passes — but note it does NOT start on its own here: GitHub suppresses + workflow runs for events raised with \`GITHUB_TOKEN\`, so a PR opened by this + workflow gets no \`pull_request\` run. Close and reopen the PR, or push an + empty commit to it, to get one. The wheel-contents leg is the one that + matters most: it fails if \`de_shell/js\` is missing, which is the whole + point of the package. ### Manual check CI cannot cover CI never runs Electron — it typechecks the TypeScript and runs the node unit