Skip to content

ci: install dependencies from uv.lock - #7

Merged
hectorvent merged 3 commits into
mainfrom
ci/install-from-uv-lock
Oct 7, 2026
Merged

hectorvent merged 3 commits into
mainfrom
ci/install-from-uv-lock

Conversation

@hectorvent

@hectorvent hectorvent commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Problem

CI installs with pip install -e ".[dev]", which ignores uv.lock and resolves the newest release of every dev tool on each run. As a result:

  • ruff 0.16.10 started formatting Python code blocks inside README.md and failed ruff format --check on chore: add pytest-timeout and refresh uv.lock #6, with no change in this repo.
  • CI and the lockfile had drifted apart: ruff 0.16.10 / testcontainers 4.15.0 in CI vs 0.15.12 / 4.14.2 in the lock.

Change

  • Replace actions/setup-python with astral-sh/setup-uv (pinned to the v10.2.0 SHA, with caching on).
  • Install with uv sync --locked --extra dev. If uv.lock is out of date with pyproject.toml, CI now fails.
  • Run ruff, mypy and pytest through uv run.
  • Set [tool.mypy] python_version to "3.10". The locked mypy 2.x rejects "3.9" and falls back to 3.10 with a warning. Ruff's py39 target and the 3.9 unit-test job still cover 3.9 compatibility.

Depends on #6

This branch includes #6's commit (pytest-timeout plus the refreshed uv.lock). Both are needed:

  • main's lock pins testcontainers 4.14.2, which ships no type hints, so mypy --strict fails with Class cannot subclass "DockerContainer".
  • The integration job passes --timeout=120, which needs pytest-timeout.

Merge #6 first, then rebase this branch so it reduces to the single CI commit.

Verified locally (against the locked versions)

  • uv lock --check passes.
  • Python 3.12: ruff check, ruff format --check, mypy floci and unit tests all pass.
  • Python 3.9: unit tests pass.
  • pytest -m integration --timeout=120 --co collects the integration tests.

@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Switches build and CI to use uv package manager.

The reviewed changes appear safe to merge.

Summary

CI now installs dependencies from uv.lock and runs checks through uv run. The latest change sets mypy's target to Python 3.10 without changing the package's Python 3.9 support.

  • Adds pytest-timeout and refreshes the lockfile, including testcontainers.
  • No actionable new issues found in the changes since the last review.
  • No previous review threads were supplied; GitHub authentication prevented retrieving them.
  • Adding greptile_confidence was attempted but blocked by missing GitHub authentication.

Reviews (2) · Last reviewed commit: "chore: set the mypy target to Python 3.1..." · Reviewed by Greptile

The CI integration job runs pytest -m integration --timeout=120, but
pytest-timeout was never a dependency, so pytest exited with
"unrecognized arguments: --timeout=120" before collecting a test. The
integration suite has not actually run in CI on any recent main build.

uv.lock also pinned testcontainers 4.14.2, which mypy treats as untyped,
so `uv sync --extra dev && uv run mypy floci` failed under strict mode
while CI (pip, testcontainers 4.15.0) passed. The lock now resolves
testcontainers 4.15.0 on Python 3.10 and later, matching CI.

Lockfile changes: pytest-timeout 2.4.0 added, testcontainers 4.14.2 to
4.15.0 (Python 3.10+). Everything else is the newer uv lockfile revision
(3 to 5) dropping redundant markers; no other version changes.

Signed-off-by: Hector Ventura <hectorvent@gmail.com>
CI ran pip install -e ".[dev]", which ignores uv.lock and pulls the
newest release of every dev tool. A ruff release that started
formatting Markdown code blocks broke the format check with no change
in this repo, and the CI and local toolchains had drifted apart
(ruff 0.16.10 in CI against 0.15.12 in the lock).

Install with uv sync --locked and run every tool through uv run, so
CI uses exactly the versions in the lockfile and fails when the lock
is out of date with pyproject.toml.

Signed-off-by: Hector Ventura <hectorvent@gmail.com>
mypy 2.x no longer accepts python_version = "3.9" and falls back to
3.10 with a warning. Set it explicitly. Ruff's py39 target and the 3.9
unit-test job still cover 3.9 compatibility, and requires-python is
unchanged.

Signed-off-by: Hector Ventura <hectorvent@gmail.com>
@hectorvent
hectorvent force-pushed the ci/install-from-uv-lock branch from b08c28d to 394b8d3 Compare October 7, 2026 01:57
@hectorvent
hectorvent merged commit 848bd82 into main Oct 7, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant