feat(cli): add sm package-update to bump simple_module_* deps - #101
Merged
Merged
Conversation
Walks the project's pyproject.toml and any [tool.uv.workspace] members, finds dependencies whose name starts with simple_module_ / simple-module-, queries PyPI for the latest non-yanked release, and rewrites each constraint to `name>=<latest>`. Deps backed by [tool.uv.sources] (workspace, path, git, url) are skipped — they aren't installed from PyPI. Flags: --path, --dry-run, --include-pre. PyPI lookups run in parallel via ThreadPoolExecutor so a project with ~10 deps takes ~100ms instead of ~1s. Mutation uses tomlkit so existing formatting is preserved. The CLI's no-extra-deps invariant (test_no_framework_deps.py pins it to typer + tomlkit) means we use a small custom version-key helper instead of pulling in `packaging`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a new
sm package-updateCLI command that walks the project'spyproject.toml(and any[tool.uv.workspace]members), finds dependencies whose distribution name starts withsimple_module_/simple-module-, queries PyPI for the latest non-yanked release, and rewrites each constraint toname>=<latest>.[tool.uv.sources](workspace = true,path,git,url) are left untouched — those aren't installed from PyPI.--include-preopts in).--dry-runshows the planned changes without writing.ThreadPoolExecutor; for a project with ~10 sm packages this is ~100ms instead of ~1s.tomlkitso existing formatting (comments, ordering, quoting) is preserved.uv sync.Why
The host scaffolds dependencies like
simple_module_core>=1.0,<2.0and there's currently no convenient way to bump them all at once when new framework / module releases land on PyPI. This gives users one command to do it.Notes for reviewers
framework/cli/tests/test_no_framework_deps.pyconstrains the CLI package totyper + tomlkit. That's why version comparison uses a tiny custom_version_keyhelper instead ofpackaging.version.Version— the latter would break the invariant. The custom helper handles standard release versions correctly; ambiguous ordering between letter-suffixed pre-releases only matters under--include-pre, which is opt-in._dep_namemirrors the more robust_parse_requirement_nameinscripts/bump_version.py(handles markers;, extras[…], all PEP 440 ops). Logic is duplicated rather than imported becausescripts/isn't packaged with the CLI wheel.run_update()is the importable entry point (accepts afetcherinjection);package_update()is the thin Typer wrapper. Keeps the--helpoutput clean and tests deterministic without hitting the network.Test plan
uv run pytest framework/cli/tests/— 94/94 passing (8 new tests).uv run ruff check+ruff format --check+ty checkclean.uv run sm package-update --helprenders cleanly with three flags.