fix: run PSR via uv to work around upstream GitPython break - #435
Conversation
python-semantic-release's GitHub Action builds its own Docker image fresh on every run and pins gitpython~=3.0 (unbounded). GitPython 3.1.60 (2026-08-25) removed Actor.name_email_regex, which PSR's config loader reads unconditionally, so every fresh build of the action's image fails with AttributeError -- confirmed on this repo's last release attempt. See python-semantic-release/python-semantic-release#1476, open, no fix released yet. Runs the same PSR version via uv instead, pinning gitpython below the break. Verified locally in --noop mode.
|
Thanks for the pull request, @irfanuddinahmad! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
openedx#435's uv-based workaround got past the GitPython crash (confirmed: correctly computed "The next version is: 4.1.1!") but hit a new failure at the build step: PSR's build_command shelled out to 'python -m pip install --upgrade build', and uv's ephemeral venvs deliberately don't bundle pip the way a stdlib venv does. Rather than add pip back in (which would undercut the point of this whole pip->uv migration), switch build_command itself to 'uv build' -- no pip anywhere. Verified locally through the full real uvx-wrapped PSR execution (not just uv build standalone): produces the correct dist/ artifacts with no pip involved at any point.
python-semantic-release/python-semantic-release#1477 (merged 2026-08-28, released in v10.6.2) fixes the GitPython 3.1.60 break that #435/#436 worked around. Reverts both back to using the official Docker action (bumped v10.6.1 -> v10.6.2) and its pip-based build_command, since the Docker image doesn't have uv available. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
#434's release run (df86ef9) failed -- not from that fix, but from a separate, unrelated upstream break:
python-semantic-release's GitHub Action builds its own Docker image fresh on every run and pinsgitpython~=3.0(unbounded), so it always installs the latest 3.x release. GitPython 3.1.60 (released 2026-08-25) removedActor.name_email_regex, which PSR's config loader reads unconditionally -- breaking every fresh build of the action's image, regardless of which PSR version is pinned.Tracked upstream: python-semantic-release/python-semantic-release#1476, fix open in #1477 but not yet merged/released.
Since we can't inject a dependency constraint into that Docker build from here, this runs the same PSR version (10.6.1) ourselves via
uv, where we can pingitpython<3.1.60. Verified locally against this repo in--noopmode -- resolves cleanly, computes the correct next version, no crash.Safe to revert back to the
uses: python-semantic-release/python-semantic-release@...action once upstream ships a fix.