Skip to content

Commit 92a12ed

Browse files
ci: the lockfile's copy of the version is checked too (#118)
The lint step's own comment says why the version is checked: declared in two places, `pip show` and `import` disagree if they drift. There is a third copy -- `uv.lock` carries an entry for this project -- and it drifted. 0.1.6 and 0.1.7 both shipped with a lockfile saying 0.1.5, because nothing re-locked after the bump and nothing looked. `uv lock` fixes the stale line. The guard is what stops the next one: the step now parses uv.lock too and refuses a mismatch, naming `uv lock` as the remedy. It also refuses anything other than exactly one entry for grapharc, so a rename cannot make the check silently vacuous. Milder than the other two copies -- it misreports the project to a reader of the lockfile and to `uv sync --locked`, not to an installed import -- but it is the same class of bug, and a version declared in N places drifts in N-1 of them. Verified: the new check passes on this tree and is red against main's lockfile (says 0.1.5, pyproject says 0.1.7), which is the drift it exists to catch. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent cf984f7 commit 92a12ed

2 files changed

Lines changed: 26 additions & 3 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 25 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,10 +27,20 @@ jobs:
2727
run: uv sync --all-extras --group dev
2828
- name: Lint
2929
run: uv run ruff check .
30-
- name: Version is declared twice; the two must agree
30+
- name: Version is declared three times; all three must agree
3131
# `grapharc.__version__` is a separate literal from the packaged
3232
# version. If they drift, `pip show` and `import` disagree about what
3333
# is installed. Parsed rather than imported, so this needs no deps.
34+
#
35+
# `uv.lock` carries a third copy, in its own entry for this project.
36+
# This step checked only the first two, and the third drifted: 0.1.6
37+
# and 0.1.7 both shipped with a lockfile saying 0.1.5, because nothing
38+
# re-locked after the bump and nothing looked. `uv lock` fixes it in
39+
# one line; what this catches is the next one. A stale copy there is
40+
# milder than the other two -- it misreports the project to anyone
41+
# reading the lockfile, and to `uv sync --locked`, rather than to an
42+
# installed import -- but it is the same class of bug, and this step
43+
# exists because a version declared in N places drifts in N-1 of them.
3444
run: |
3545
python3 - <<'PY'
3646
import ast
@@ -55,7 +65,20 @@ jobs:
5565
sys.exit("grapharc/__init__.py no longer declares __version__")
5666
if declared != packaged:
5767
sys.exit(f"grapharc.__version__ is {declared!r} but pyproject says {packaged!r}")
58-
print(f"ok: version {packaged} declared in both places")
68+
69+
with open("uv.lock", "rb") as fh:
70+
lock = tomllib.load(fh)
71+
72+
entries = [p for p in lock.get("package", []) if p.get("name") == "grapharc"]
73+
if len(entries) != 1:
74+
sys.exit(f"uv.lock has {len(entries)} entries for grapharc; expected exactly 1")
75+
locked = entries[0].get("version")
76+
if locked != packaged:
77+
sys.exit(
78+
f"uv.lock says grapharc is {locked!r} but pyproject says "
79+
f"{packaged!r} -- run `uv lock` and commit the result"
80+
)
81+
print(f"ok: version {packaged} declared in all three places")
5982
PY
6083
6184
live-marker-guard:

‎uv.lock‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)