fix(deps): licensecheck reports 0 packages and fails CI with exit code 3 - #1108
Merged
Merged
Conversation
Root cause (verified by reading licensecheck 2026.0.8's source): - licensecheck's CLI unconditionally resets requirements_paths back to ["pyproject.toml"] whenever --requirements-paths isn't passed explicitly on the command line, silently discarding [tool.licensecheck].requirements_paths from pyproject.toml. - Our root pyproject.toml's only direct dependencies are our own workspace packages, all of which are in skip_dependencies (needed to avoid a crash on editable -e file:// entries). With only pyproject.toml as the entry point, zero real third-party packages are ever discovered -> "No packages" -> exit code 3 (NO_PACKAGES). Fix: pass --requirements-paths explicitly in poe_tasks.toml, including each workspace member's own pyproject.toml (their real, non-internal dependencies), so licensecheck always has real packages to walk regardless of this CLI quirk. Also: - Point licensecheck-third-party's --file at THIRD_PARTY_NOTICES.md, the actual tracked doc (the task was writing to a different, untracked filename). - Regenerate THIRD_PARTY_NOTICES.md with current, accurate data (it was stale, generated by licensecheck 2025.1.0 against long-outdated package versions). Verified locally: poe licensecheck --check now scans 55 packages and exits 0; poe reuse still passes. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
|
MvLieshout
enabled auto-merge (squash)
September 28, 2026 10:57
egordm
approved these changes
Sep 28, 2026
MvLieshout
added a commit
that referenced
this pull request
Sep 28, 2026
…e 3 (#1108) ## What does this PR do? Fixes `poe licensecheck --check` (and thus the `Quality Checks` CI job) failing on `main` with exit code 3 ("No packages"). Root cause (verified by reading `licensecheck` 2026.0.8's source directly): - `licensecheck`'s CLI unconditionally resets `requirements_paths` back to `["pyproject.toml"]` whenever `--requirements-paths` isn't passed explicitly on the command line, silently discarding `[tool.licensecheck].requirements_paths` set in `pyproject.toml`. - Our root `pyproject.toml`'s only direct dependencies are our own workspace packages, all of which are listed in `skip_dependencies` (needed to avoid a crash on the editable `-e file://` entries `uv` emits for them). With only `pyproject.toml` as the entry point, every discovered top-level requirement gets filtered out by `skip_dependencies` before its transitive (real, third-party) dependencies are ever walked — so licensecheck resolves zero packages and exits 3. Fix: pass `--requirements-paths` explicitly in `poe_tasks.toml`, including each workspace member's own `pyproject.toml` (their real, non-internal dependencies), so licensecheck always has real packages to walk regardless of this CLI quirk. Also: - Point `licensecheck-third-party`'s `--file` at `THIRD_PARTY_NOTICES.md`, the actual tracked doc (the task was writing to a different, untracked filename, `THIRD_PARTY_LICENSES.md`). - Regenerate `THIRD_PARTY_NOTICES.md` with current, accurate data — it was stale, last generated by `licensecheck` 2025.1.0 against long-outdated package versions. Verified locally: `poe licensecheck --check` now scans 55 packages and exits 0; `poe reuse` and `poe format-pyproject --check` still pass. Closes # ## Type of change - [x] Bug fix - [ ] New feature - [ ] Breaking change (see checklist below) - [ ] Documentation - [ ] Refactor / chore / CI ## Breaking changes checklist - [ ] Public API, config schema, or serialized/pickled objects changed in a way that affects existing users ## AI disclosure - [ ] No AI assistance was used (beyond grammar/spelling) - [x] AI assistance was used — tool(s): GitHub Copilot - [x] I have reviewed, understand, and can explain all AI-generated code in this PR - [x] This is disclosed in a commit message (e.g. `Assisted-by: <tool name>`) ## Checklist - [x] `poe all --check` passes locally (verified the affected tasks: `licensecheck --check`, `reuse`, `format-pyproject --check`) - [ ] Tests added/updated for the change - [ ] Documentation updated (docstrings, user guide, examples) if needed - [x] Commits are signed off per our DCO (`git commit -s`) - [x] PR title follows Conventional Commits Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What does this PR do?
Fixes
poe licensecheck --check(and thus theQuality ChecksCI job) failing onmainwith exit code 3 ("No packages").Root cause (verified by reading
licensecheck2026.0.8's source directly):licensecheck's CLI unconditionally resetsrequirements_pathsback to["pyproject.toml"]whenever--requirements-pathsisn't passed explicitly on the command line, silently discarding[tool.licensecheck].requirements_pathsset inpyproject.toml.pyproject.toml's only direct dependencies are our own workspace packages, all of which are listed inskip_dependencies(needed to avoid a crash on the editable-e file://entriesuvemits for them). With onlypyproject.tomlas the entry point, every discovered top-level requirement gets filtered out byskip_dependenciesbefore its transitive (real, third-party) dependencies are ever walked — so licensecheck resolves zero packages and exits 3.Fix: pass
--requirements-pathsexplicitly inpoe_tasks.toml, including each workspace member's ownpyproject.toml(their real, non-internal dependencies), so licensecheck always has real packages to walk regardless of this CLI quirk.Also:
licensecheck-third-party's--fileatTHIRD_PARTY_NOTICES.md, the actual tracked doc (the task was writing to a different, untracked filename,THIRD_PARTY_LICENSES.md).THIRD_PARTY_NOTICES.mdwith current, accurate data — it was stale, last generated bylicensecheck2025.1.0 against long-outdated package versions.Verified locally:
poe licensecheck --checknow scans 55 packages and exits 0;poe reuseandpoe format-pyproject --checkstill pass.Closes #
Type of change
Breaking changes checklist
AI disclosure
Assisted-by: <tool name>)Checklist
poe all --checkpasses locally (verified the affected tasks:licensecheck --check,reuse,format-pyproject --check)git commit -s)