ci: install CI dependencies from hash-pinned locks - #101
Merged
Conversation
Same pattern as trace-registry. Every pip install in these workflows resolved whatever PyPI served at that moment, which is what Scorecard's pipCommand-not-pinned findings are. Three locks under requirements/, each compiled from a .in whose header carries the exact regeneration command, all installed with --require-hashes. That flag is all-or-nothing: pip refuses if any requirement, transitive included, lacks a hash. The editable installs use the two-step. pip cannot hash-pin an editable install in the same invocation, so third-party dependencies come from the lock first and the local package goes in with --no-deps, leaving nothing to resolve. Locks are universal rather than platform-specific and compiled against 3.11, the floor in requires-python, so they hold across the whole 3.11/3.12/3.13 matrix. Verified in a clean venv: the lock installs under --require-hashes and the full suite passes, 629 passed and 5 xpassed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same pattern as agentrust-io/trace-registry#67, which is merged and green.
Every
pip installin these workflows resolved whatever PyPI served at that moment. Three locks underrequirements/, each compiled from a.inwhose header carries the exact regeneration command:test.txt[project.dependencies]plus thetestextradocs.txtrelease.txtbuildAll installed with
--require-hashes, which is all-or-nothing: pip refuses if any requirement, transitive included, lacks a hash.The editable installs use the two-step, since pip cannot hash-pin an editable install in the same invocation:
Locks are universal and compiled against 3.11, the floor in
requires-python, so they hold across the whole 3.11/3.12/3.13 matrix rather than only the version they were generated on.Verification
Clean venv: the lock installs under
--require-hashes, the editable install follows, and the full suite passes — 629 passed, 5 xpassed. actionlint clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t