fix: build with uv instead of pip in the uv-run PSR step - #436
Conversation
|
Thanks for the pull request, @irfanuddinahmad! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
openedx#435's uv-based workaround got past the GitPython crash (confirmed: correctly computed "The next version is: 4.1.1!") but hit a new failure at the build step: PSR's build_command shelled out to 'python -m pip install --upgrade build', and uv's ephemeral venvs deliberately don't bundle pip the way a stdlib venv does. Rather than add pip back in (which would undercut the point of this whole pip->uv migration), switch build_command itself to 'uv build' -- no pip anywhere. Verified locally through the full real uvx-wrapped PSR execution (not just uv build standalone): produces the correct dist/ artifacts with no pip involved at any point.
09c9a25 to
66b85c8
Compare
python-semantic-release/python-semantic-release#1477 (merged 2026-08-28, released in v10.6.2) fixes the GitPython 3.1.60 break that #435/#436 worked around. Reverts both back to using the official Docker action (bumped v10.6.1 -> v10.6.2) and its pip-based build_command, since the Docker image doesn't have uv available. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ormance release.yml (added in #425, touched again in #434/#435/#436/#438) had drifted from the org's gold-standard reference (sample-plugin's release.yml): python-semantic-release, actions/upload-artifact and actions/download-artifact were on floating version tags (@v10.6.2, @v7, @v8) instead of pinned commit SHAs, defeating the whole point of the pin-actions-to-sha effort (this repo's own #407) for the one workflow that runs unreviewed on every push to master. Also: - Drop `fetch-depth: 0` from the release job's checkout: python-semantic- release auto-deepens a shallow clone itself before evaluating version history, so it's never needed here (confirmed against sample-plugin). - Add `if-no-files-found: error` to the dist upload step so a build that silently produces no artifacts fails loudly instead of shipping an empty release. - Add the `github.ref_name == 'master'` guard to publish_to_pypi's `if:`, matching sample-plugin, even though this workflow currently only triggers on push to master. All three added SHAs were independently verified against the upstream repos via `gh api repos/<owner>/<repo>/commits/<sha>` and cross-checked against their claimed tags (resolving through the annotated tag object for python-semantic-release@v10.6.2, which points at commit 9a026e9303981c866c3425723009becb2437c757). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
#435's uv-based workaround got past the GitPython crash (confirmed: this run correctly computed "The next version is: 4.1.1!") but hit a new failure at the build step: https://github.com/openedx/event-tracking/actions/runs/33071634441
PSR's
build_command(pyproject.toml) shells out topython -m pip install --upgrade build, butuv's ephemeral venvs deliberately don't bundle pip the way a stdlib venv/virtualenv does.Verified locally through the full real
uvx-wrapped PSR execution, not justuv buildstandalone: produces the correctdist/*.tar.gz/*.whlartifacts.