Skip to content

ci: bump setup-uv to v10.2.0 and sync the pinned-SHA contract test - #229

Merged
sumitake merged 1 commit into
mainfrom
cursor/setup-uv-10.2.0-companion-d8e7
Sep 28, 2026
Merged

sumitake merged 1 commit into
mainfrom
cursor/setup-uv-10.2.0-companion-d8e7

Conversation

@sumitake

@sumitake sumitake commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

Companion for Dependabot #228 (astral-sh/setup-uv 10.1.0 → 10.2.0). That PR only updates .github/workflows/release.yml and fails CI because tests/test_ci_security_contract.py::test_release_provisions_pinned_uv_before_schema_validation still hardcodes the old SHA.

This branch applies the same pin and updates the contract test so CI can go green. The installed uv version remains '0.12.5', still required before schema validation. The pin c18668ad3cf93ea998bef934396af7bb5c839dc7 is the official v10.2.0 tag commit on astral-sh/setup-uv.

Ops can close #228 after this merges. Do not merge #228. Do not push onto dependabot/**.

Boundary declaration

  • No provider executor source, raw provider command, credential, private absolute path, retired package tree, downloader, or post-install hook is included.
  • Native-runtime changes, if any, contain only a final signed artifact and reviewed public verification metadata; implementation and credentials remain private.
  • The change does not create a host-specific preset or provider-specific plugin.

Generated and release surfaces

  • Skill specs and generated SKILL.md files are in parity. (unchanged)
  • Claude and Codex marketplaces/manifests are in parity. (unchanged)
  • A unique changelog.d/ fragment is present for a user-visible change; generated CHANGELOG.md changes only in a release/bootstrap PR. (not user-visible; CI pin + test only)
  • Version metadata is bumped when behavior or distributed content changes. (no package behavior or distributed content change)

Verification

  • python3 -m unittest tests.test_ci_security_contract.CiSecurityContractTests -v — 13 tests OK locally, including test_release_provisions_pinned_uv_before_schema_validation
  • git diff --check — clean
  • Remaining repository gates run in PR CI.

Review and post-condition

Tier 2 (ordinary CI dependency pin + matching test). No independent-family review is claimed in this opening. After merge, required checks should be green on main; then close #228.

Compliance trace

author: cursor (Grok 4.7)
standing_directives: Read AGENTS.md and public governance; keep the change limited to the release.yml setup-uv pin and matching security-contract test; never push dependabot/**.
tier: 2
cross_check: AWAITING independent-family review of the setup-uv v10.2.0 pin (c18668ad3cf93ea998bef934396af7bb5c839dc7) and matching contract test.
post_condition: After operator merge, confirm main uses the v10.2.0 setup-uv pin, the contract test matches, required CI is green, and Dependabot #228 can be closed.
mcp_coverage_gap: NONE
contributor_rights: OWNER-AUTHORED
operator_reserved: yes - .github/workflows/release.yml is reserved by CODEOWNERS; operator must merge.

Open in Web Open in Cursor 

Companion for Dependabot #228. Keep uv 0.12.5 and assert the new
pinned SHA so the release security contract stays in sync.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: e04dd17c-d1e4-4379-8234-fc664e4adc19


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T14:26:50.777736Z 3acd1be PR opened
🔒 Security Review ✅ Completed 2026-09-28T14:28:40.434901Z 3acd1be PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sumitake
sumitake merged commit 86b883a into main Sep 28, 2026
20 checks passed
@sumitake
sumitake deleted the cursor/setup-uv-10.2.0-companion-d8e7 branch September 28, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants