Skip to content

PS-1669: pin Poetry 2.5.1 - #17

Merged
stephen-kintsugi merged 2 commits into
mainfrom
task/PS-1669/poetry-2-5-1
Oct 7, 2026
Merged

stephen-kintsugi merged 2 commits into
mainfrom
task/PS-1669/poetry-2-5-1

Conversation

@stephen-kintsugi

@stephen-kintsugi stephen-kintsugi commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This repo installs Poetry 2.1.3. 2.1.x has CVE-2026-34591 (wheel path traversal, fixed in 2.3.3), and with virtualenv 20.33 or later it builds venvs on Poetry's own Python. Every repo, CI job, image, and laptop is moving to Poetry 2.5.1 (LDR-9), so CI here builds the same way as laptops and docker-base.

  • .github/actions/setup-python-poetry pins 2.5.1

Jira

PS-1669

Tests

  • CI on this PR runs with the new pin.
  • Poetry 2.5.1 writes lock-version = "2.1" and reads locks from 2.1.x through 2.4.x, so the existing poetry.lock is unchanged.

Document Checklist

N/A

🤖 Generated with Claude Code


Note

Low Risk
Toolchain-only version bumps with no application or dependency lockfile changes in the diff.

Overview
Upgrades Poetry from 2.1.3 to 2.5.1 in CI and local hooks so builds match the org-wide pin and avoid CVE-2026-34591 in Poetry 2.1.x.

The composite action setup-python-poetry now installs Poetry 2.5.1. .pre-commit-config.yaml uses the same Poetry revision for poetry-check and sets the default pre-commit Python runtime to python3.13 (aligned with the action’s default Python version). No poetry.lock changes are expected in this PR.

Reviewed by Cursor Bugbot for commit 87f50c2. Bugbot is set up for automated code reviews on this repo. Configure here.

stephen-kintsugi and others added 2 commits October 6, 2026 20:19
CI installed 2.1.3, which has CVE-2026-34591 and builds venvs on the wrong Python with virtualenv 20.33+. Every repo, CI job, image, and laptop moves to 2.5.1 (LDR-9).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI-Tool: Claude Code CLI
AI-Model: claude-opus-5-5
AI-Reasoning: medium
The python-poetry hook was pinned to 2.1.3 and hook environments to python3.12, so poetry-check ran a different Poetry than CI and laptops and needed a Python most machines do not select. The library support range and CI matrix are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI-Tool: Claude Code CLI
AI-Model: claude-opus-5-5
AI-Reasoning: medium

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk assessment: Low — approved

Verified from the diff (not the PR description): two toolchain/config files only.

  • .github/actions/setup-python-poetry/action.yml: Poetry CI pin 2.1.3 → 2.5.1 (one line).
  • .pre-commit-config.yaml: poetry-check hook rev 2.1.3 → 2.5.1 and default_language_version.python python3.12 → python3.13 (two lines).

Blast radius is limited to build/dev tooling; no production code, no poetry.lock change, no schema/infra/shared-resource impact, and both edits are trivially reversible. The live CI matrix on this PR validates the new pin. No new test coverage is required since no production code changed, and no import-linter allowlist changes are present.

Decision:

  • risk_level: Low
  • review_required: false
  • reviewers: (none)
  • action_taken: approved
  • rationale: Toolchain-only version bump across .github/actions/setup-python-poetry/action.yml and .pre-commit-config.yaml; no production codepaths modified, tiny and trivially reversible diff, no shared-resource contention — Low risk with no active approval, so approved.
Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers & Assess Risk & Approve if Safe

@stephen-kintsugi
stephen-kintsugi merged commit 33c2d6c into main Oct 7, 2026
10 checks passed
@stephen-kintsugi
stephen-kintsugi deleted the task/PS-1669/poetry-2-5-1 branch October 7, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant