Skip to content

ci: install CI dependencies from hash-pinned locks - #50

Merged
imran-siddique merged 1 commit into
mainfrom
ci/hash-pinned-pip
Sep 7, 2026
Merged

ci: install CI dependencies from hash-pinned locks#50
imran-siddique merged 1 commit into
mainfrom
ci/hash-pinned-pip

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Same pattern as agentrust-io/trace-registry#67 (merged, green), trace-tests#101 and trace-spec#302.

Three locks under requirements/test.txt, release.txt, sbom.txt — all installed with --require-hashes, which is all-or-nothing: pip refuses if any requirement, transitive included, lacks a hash.

The markers matter here

This is the one repo where the lock cannot be flattened. The matrix spans 3.10 to 3.13 and agentrust-trace is gated to 3.11+, so the python_version conditions are carried into the lock rather than resolved away. A flattened lock would either pull agentrust-trace onto 3.10, where it does not install, or drop it everywhere and stop testing the trace adapter at all.

Compiled against 3.10, the floor in requires-python, and universal, so one file serves the whole matrix.

Two things deliberately removed

python -m pip install --upgrade pip appeared twice. Upgrading pip to whatever is current is the same unpinned fetch this change exists to remove, and the runner ships a recent pip already. Dropped rather than pinned.

Verification

Clean venv: the lock installs under --require-hashes, the editable install follows, and the suite passes. actionlint clean.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t

Same pattern as trace-registry, trace-tests and trace-spec.

Three locks under requirements/, all installed with --require-hashes,
which is all-or-nothing: pip refuses if any requirement, transitive
included, lacks a hash.

The python_version markers are carried into the lock rather than resolved
away. This matrix spans 3.10 to 3.13 and agentrust-trace is 3.11+, so a
lock that flattened the condition would either pull agentrust-trace onto
3.10, where it does not install, or drop it everywhere. Compiled against
3.10, the floor in requires-python, and universal so one file serves the
whole matrix.

The editable installs use the two-step, since pip cannot hash-pin an
editable install in the same invocation.

The two "pip install --upgrade pip" steps are dropped rather than pinned.
Upgrading pip to whatever is current is the same unpinned fetch this
change exists to remove, and the runner's pip is already recent.

Verified in a clean venv: the lock installs under --require-hashes and
the suite passes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t
@imran-siddique
imran-siddique merged commit 9fc9580 into main Sep 7, 2026
9 checks passed
@imran-siddique
imran-siddique deleted the ci/hash-pinned-pip branch September 7, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant