Skip to content

fix(deps): licensecheck reports 0 packages and fails CI with exit code 3 - #1108

Merged
MvLieshout merged 1 commit into
mainfrom
fix/licensecheck-no-packages
Sep 28, 2026
Merged

MvLieshout merged 1 commit into
mainfrom
fix/licensecheck-no-packages

Conversation

@MvLieshout

Copy link
Copy Markdown
Collaborator

What does this PR do?

Fixes poe licensecheck --check (and thus the Quality Checks CI job) failing on main with exit code 3 ("No packages").

Root cause (verified by reading licensecheck 2026.0.8's source directly):

  • licensecheck's CLI unconditionally resets requirements_paths back to ["pyproject.toml"] whenever --requirements-paths isn't passed explicitly on the command line, silently discarding [tool.licensecheck].requirements_paths set in pyproject.toml.
  • Our root pyproject.toml's only direct dependencies are our own workspace packages, all of which are listed in skip_dependencies (needed to avoid a crash on the editable -e file:// entries uv emits for them). With only pyproject.toml as the entry point, every discovered top-level requirement gets filtered out by skip_dependencies before its transitive (real, third-party) dependencies are ever walked — so licensecheck resolves zero packages and exits 3.

Fix: pass --requirements-paths explicitly in poe_tasks.toml, including each workspace member's own pyproject.toml (their real, non-internal dependencies), so licensecheck always has real packages to walk regardless of this CLI quirk.

Also:

  • Point licensecheck-third-party's --file at THIRD_PARTY_NOTICES.md, the actual tracked doc (the task was writing to a different, untracked filename, THIRD_PARTY_LICENSES.md).
  • Regenerate THIRD_PARTY_NOTICES.md with current, accurate data — it was stale, last generated by licensecheck 2025.1.0 against long-outdated package versions.

Verified locally: poe licensecheck --check now scans 55 packages and exits 0; poe reuse and poe format-pyproject --check still pass.

Closes #

Type of change

  • Bug fix
  • New feature
  • Breaking change (see checklist below)
  • Documentation
  • Refactor / chore / CI

Breaking changes checklist

  • Public API, config schema, or serialized/pickled objects changed in a way that affects existing users

AI disclosure

  • No AI assistance was used (beyond grammar/spelling)
  • AI assistance was used — tool(s): GitHub Copilot
    • I have reviewed, understand, and can explain all AI-generated code in this PR
    • This is disclosed in a commit message (e.g. Assisted-by: <tool name>)

Checklist

  • poe all --check passes locally (verified the affected tasks: licensecheck --check, reuse, format-pyproject --check)
  • Tests added/updated for the change
  • Documentation updated (docstrings, user guide, examples) if needed
  • Commits are signed off per our DCO (git commit -s)
  • PR title follows Conventional Commits

Root cause (verified by reading licensecheck 2026.0.8's source):
- licensecheck's CLI unconditionally resets requirements_paths back to
  ["pyproject.toml"] whenever --requirements-paths isn't passed
  explicitly on the command line, silently discarding
  [tool.licensecheck].requirements_paths from pyproject.toml.
- Our root pyproject.toml's only direct dependencies are our own
  workspace packages, all of which are in skip_dependencies (needed to
  avoid a crash on editable -e file:// entries). With only
  pyproject.toml as the entry point, zero real third-party packages are
  ever discovered -> "No packages" -> exit code 3 (NO_PACKAGES).

Fix: pass --requirements-paths explicitly in poe_tasks.toml, including
each workspace member's own pyproject.toml (their real, non-internal
dependencies), so licensecheck always has real packages to walk
regardless of this CLI quirk.

Also:
- Point licensecheck-third-party's --file at THIRD_PARTY_NOTICES.md,
  the actual tracked doc (the task was writing to a different,
  untracked filename).
- Regenerate THIRD_PARTY_NOTICES.md with current, accurate data (it was
  stale, generated by licensecheck 2025.1.0 against long-outdated
  package versions).

Verified locally: poe licensecheck --check now scans 55 packages and
exits 0; poe reuse still passes.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
@MvLieshout
MvLieshout requested a review from a team September 28, 2026 10:05
@MvLieshout MvLieshout added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@github-actions github-actions Bot added the fix Something isn't working label Sep 28, 2026
@sonarqubecloud

Copy link
Copy Markdown

@MvLieshout
MvLieshout enabled auto-merge (squash) September 28, 2026 10:57
@MvLieshout
MvLieshout merged commit 16d2560 into main Sep 28, 2026
8 checks passed
@MvLieshout
MvLieshout deleted the fix/licensecheck-no-packages branch September 28, 2026 11:01
MvLieshout added a commit that referenced this pull request Sep 28, 2026
…e 3 (#1108)

## What does this PR do?

Fixes `poe licensecheck --check` (and thus the `Quality Checks` CI job)
failing on `main` with exit code 3 ("No packages").

Root cause (verified by reading `licensecheck` 2026.0.8's source
directly):
- `licensecheck`'s CLI unconditionally resets `requirements_paths` back
to `["pyproject.toml"]` whenever `--requirements-paths` isn't passed
explicitly on the command line, silently discarding
`[tool.licensecheck].requirements_paths` set in `pyproject.toml`.
- Our root `pyproject.toml`'s only direct dependencies are our own
workspace packages, all of which are listed in `skip_dependencies`
(needed to avoid a crash on the editable `-e file://` entries `uv` emits
for them). With only `pyproject.toml` as the entry point, every
discovered top-level requirement gets filtered out by
`skip_dependencies` before its transitive (real, third-party)
dependencies are ever walked — so licensecheck resolves zero packages
and exits 3.

Fix: pass `--requirements-paths` explicitly in `poe_tasks.toml`,
including each workspace member's own `pyproject.toml` (their real,
non-internal dependencies), so licensecheck always has real packages to
walk regardless of this CLI quirk.

Also:
- Point `licensecheck-third-party`'s `--file` at
`THIRD_PARTY_NOTICES.md`, the actual tracked doc (the task was writing
to a different, untracked filename, `THIRD_PARTY_LICENSES.md`).
- Regenerate `THIRD_PARTY_NOTICES.md` with current, accurate data — it
was stale, last generated by `licensecheck` 2025.1.0 against
long-outdated package versions.

Verified locally: `poe licensecheck --check` now scans 55 packages and
exits 0; `poe reuse` and `poe format-pyproject --check` still pass.

Closes #

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change (see checklist below)
- [ ] Documentation
- [ ] Refactor / chore / CI

## Breaking changes checklist

- [ ] Public API, config schema, or serialized/pickled objects changed
in a way that affects existing users

## AI disclosure

- [ ] No AI assistance was used (beyond grammar/spelling)
- [x] AI assistance was used — tool(s): GitHub Copilot
- [x] I have reviewed, understand, and can explain all AI-generated code
in this PR
- [x] This is disclosed in a commit message (e.g. `Assisted-by: <tool
name>`)

## Checklist

- [x] `poe all --check` passes locally (verified the affected tasks:
`licensecheck --check`, `reuse`, `format-pyproject --check`)
- [ ] Tests added/updated for the change
- [ ] Documentation updated (docstrings, user guide, examples) if needed
- [x] Commits are signed off per our DCO (`git commit -s`)
- [x] PR title follows Conventional Commits

Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file fix Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants