Skip to content

chore(deps): 🔧 relax dependency floors and test them in CI - #54

Merged
Panadestein merged 1 commit into
mainfrom
chore/18-dependency-floors
Oct 6, 2026
Merged

Panadestein merged 1 commit into
mainfrom
chore/18-dependency-floors

Conversation

@Panadestein

Copy link
Copy Markdown
Member

🤖 AI text below 🤖

Closes #18.

Dependency floors

I found the floors by running the fast suite on Python 3.11 against older releases:

Constraint Before After Notes
numpy (runtime) >=2.4.4,<3 >=2.0,<3 2.0.0, 2.0.2, 2.1.3 and 2.2.6 all pass. 1.26.4 passes too, but I kept the <3 cap and a NumPy-2 floor as the issue proposes, since NumPy 2 changed how dtypes are promoted (NEP 50).
quimb (test group) >=1.14.0,<2 >=1.8.3,<2 1.8.0–1.8.2 fail test_*_precision[float32-MPO_rand] because MPO_rand ignores float32 there.

opt_einsum>=3.4.0 is already the latest release, so I left it alone.

Floors tested in CI

test.yml gets an extra matrix entry on ubuntu-latest / Python 3.11 with UV_RESOLUTION=lowest-direct. It sets the variable for the whole job, so the later uv run steps don't re-sync to the lockfile. That job resolves numpy==2.0.0, quimb==1.8.3, opt_einsum==3.4.0, pytest==9.1.0 and so on. I ran the same commands locally, including --cov, and the whole suite passes. Artifact labels now include the resolution so they stay unique.

Ruff pin

The ruff part of the issue was mostly fixed already: there is one prek.toml (no .pre-commit-config.yaml), and update-ruff.yml bumps both pins. What was missing is the check that fails when they drift apart. This PR adds:

  • .github/scripts/check_tool_pins.py, run as the local check-tool-pins prek hook whenever pyproject.toml or prek.toml changes. It compares the ruff== and ty== pins in the dependency groups with the rev of their pre-commit mirrors. I checked that it fails on a deliberately wrong ty rev.

Docs

There is a new "Version constraints" section in docs/developer-guide/dependencies.md. It covers the floor policy, how to reproduce the lowest-resolution job locally, and the pin check.

Notes

@Panadestein

Copy link
Copy Markdown
Member Author

🤖 AI text below 🤖

Rebased onto main now that #53 is merged. The new bench group's quimb pin is also lowered to >=1.8.3,<2, and uv.lock is regenerated.

@Panadestein
Panadestein force-pushed the chore/18-dependency-floors branch from 09b18e1 to b7fb5e3 Compare October 6, 2026 13:32
numpy goes from >=2.4.4 to >=2.0 and quimb from >=1.14.0 to >=1.8.3, the oldest
releases the suite passes on (quimb 1.8.0-1.8.2 ignore float32 in MPO_rand). A
new test job on Python 3.11 resolves every direct dependency to its lowest
allowed version so the floors stay tested. A check-tool-pins prek hook fails if
the ruff or ty pins in pyproject.toml and prek.toml disagree.

Closes #18

Assisted-by: pi:claude-opus-5.5
@Panadestein
Panadestein force-pushed the chore/18-dependency-floors branch from b7fb5e3 to 6622280 Compare October 6, 2026 15:43
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Test Results

  5 files  +  1    5 suites  +1   2m 51s ⏱️ +54s
135 tests ±  0  134 ✅ ±  0  1 💤 ±0  0 ❌ ±0 
640 runs  +124  637 ✅ +123  3 💤 +1  0 ❌ ±0 

Results for commit 6622280. ± Comparison against base commit ee40429.

@Panadestein

Copy link
Copy Markdown
Member Author

🤖 AI text below 🤖

Fixed the failing CI and rebased onto main.

  • Why the oldest-versions job failed: scipy in the bench group from chore(deps): 🔧 move benchmark-only dependencies to a bench group #53 had no lower bound, so lowest-version resolution picked scipy==1.0.0. The uv run steps then synced the dev group, which includes bench, and that scipy fails to build on Python 3.11. Fail-fast then cancelled the other test jobs.
  • Fix:
    • The test job sets UV_NO_SYNC=1, so uv run uses the environment built by uv sync --no-dev --group test.
    • Every direct dependency that had no lower bound now has one: scipy>=1.13, scalene>=1.5, pylatexenc>=2.10, nbconvert>=7, pytest-markdown-docs>=0.9.
  • Conflict with docs: 📝 replace the MkDocs site with a Fumadocs site #56: the version-constraints section now lives in docs/content/docs/contributing/dependencies.mdx, with the reproduce commands updated to use --no-sync.

All checks pass now, including lowest-direct (numpy 2.0.0, quimb 1.8.3, scipy 1.13.0).

@Panadestein
Panadestein merged commit bcf7e96 into main Oct 6, 2026
15 checks passed
@Panadestein
Panadestein deleted the chore/18-dependency-floors branch October 6, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Relax over-tight dependency floors and single-source the ruff pin

1 participant