ci: install CI dependencies from hash-pinned locks - #50
Merged
Conversation
Same pattern as trace-registry, trace-tests and trace-spec. Three locks under requirements/, all installed with --require-hashes, which is all-or-nothing: pip refuses if any requirement, transitive included, lacks a hash. The python_version markers are carried into the lock rather than resolved away. This matrix spans 3.10 to 3.13 and agentrust-trace is 3.11+, so a lock that flattened the condition would either pull agentrust-trace onto 3.10, where it does not install, or drop it everywhere. Compiled against 3.10, the floor in requires-python, and universal so one file serves the whole matrix. The editable installs use the two-step, since pip cannot hash-pin an editable install in the same invocation. The two "pip install --upgrade pip" steps are dropped rather than pinned. Upgrading pip to whatever is current is the same unpinned fetch this change exists to remove, and the runner's pip is already recent. Verified in a clean venv: the lock installs under --require-hashes and the suite passes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same pattern as agentrust-io/trace-registry#67 (merged, green), trace-tests#101 and trace-spec#302.
Three locks under
requirements/—test.txt,release.txt,sbom.txt— all installed with--require-hashes, which is all-or-nothing: pip refuses if any requirement, transitive included, lacks a hash.The markers matter here
This is the one repo where the lock cannot be flattened. The matrix spans 3.10 to 3.13 and
agentrust-traceis gated to 3.11+, so thepython_versionconditions are carried into the lock rather than resolved away. A flattened lock would either pullagentrust-traceonto 3.10, where it does not install, or drop it everywhere and stop testing the trace adapter at all.Compiled against 3.10, the floor in
requires-python, and universal, so one file serves the whole matrix.Two things deliberately removed
python -m pip install --upgrade pipappeared twice. Upgrading pip to whatever is current is the same unpinned fetch this change exists to remove, and the runner ships a recent pip already. Dropped rather than pinned.Verification
Clean venv: the lock installs under
--require-hashes, the editable install follows, and the suite passes. actionlint clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01XbDBXDWWvMFa7c2jGgyq9t