Repository navigation
PS-1669: pin Poetry 2.5.1 - #17
Merged
Merged
Conversation
CI installed 2.1.3, which has CVE-2026-34591 and builds venvs on the wrong Python with virtualenv 20.33+. Every repo, CI job, image, and laptop moves to 2.5.1 (LDR-9). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> AI-Tool: Claude Code CLI AI-Model: claude-opus-5-5 AI-Reasoning: medium
The python-poetry hook was pinned to 2.1.3 and hook environments to python3.12, so poetry-check ran a different Poetry than CI and laptops and needed a Python most machines do not select. The library support range and CI matrix are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> AI-Tool: Claude Code CLI AI-Model: claude-opus-5-5 AI-Reasoning: medium
There was a problem hiding this comment.
Risk assessment: Low — approved
Verified from the diff (not the PR description): two toolchain/config files only.
.github/actions/setup-python-poetry/action.yml: Poetry CI pin2.1.3→2.5.1(one line)..pre-commit-config.yaml:poetry-checkhook rev2.1.3→2.5.1anddefault_language_version.pythonpython3.12→python3.13(two lines).
Blast radius is limited to build/dev tooling; no production code, no poetry.lock change, no schema/infra/shared-resource impact, and both edits are trivially reversible. The live CI matrix on this PR validates the new pin. No new test coverage is required since no production code changed, and no import-linter allowlist changes are present.
Decision:
risk_level: Lowreview_required: falsereviewers: (none)action_taken: approvedrationale: Toolchain-only version bump across.github/actions/setup-python-poetry/action.ymland.pre-commit-config.yaml; no production codepaths modified, tiny and trivially reversible diff, no shared-resource contention — Low risk with no active approval, so approved.
Sent by Cursor Automation: Assign PR reviewers & Assess Risk & Approve if Safe
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
This repo installs Poetry 2.1.3. 2.1.x has CVE-2026-34591 (wheel path traversal, fixed in 2.3.3), and with virtualenv 20.33 or later it builds venvs on Poetry's own Python. Every repo, CI job, image, and laptop is moving to Poetry 2.5.1 (LDR-9), so CI here builds the same way as laptops and docker-base.
.github/actions/setup-python-poetrypins 2.5.1Jira
PS-1669
Tests
lock-version = "2.1"and reads locks from 2.1.x through 2.4.x, so the existingpoetry.lockis unchanged.Document Checklist
N/A
🤖 Generated with Claude Code
Note
Low Risk
Toolchain-only version bumps with no application or dependency lockfile changes in the diff.
Overview
Upgrades Poetry from 2.1.3 to 2.5.1 in CI and local hooks so builds match the org-wide pin and avoid CVE-2026-34591 in Poetry 2.1.x.
The composite action
setup-python-poetrynow installs Poetry 2.5.1..pre-commit-config.yamluses the same Poetry revision forpoetry-checkand sets the default pre-commit Python runtime to python3.13 (aligned with the action’s default Python version). Nopoetry.lockchanges are expected in this PR.Reviewed by Cursor Bugbot for commit 87f50c2. Bugbot is set up for automated code reviews on this repo. Configure here.