Repository navigation
Regenerate requirements.txt from uv.lock - #101
Merged
dillonbbailey merged 1 commit intoSep 29, 2026
Merged
dillonbbailey merged 1 commit into
dillonbbailey merged 1 commit into
Conversation
requirements.txt was last refreshed for v1.5.1 in December 2025, while uv.lock has moved on to v1.6.2. Nothing in the repo consumes requirements.txt -- both CI jobs install with uv sync -- so the drift went unnoticed, but SCA tooling still reads it as a manifest and reports vulnerabilities against versions the project no longer installs. Most significantly it advertised usd-core 25.5, which carries GHSA-58p5-r2f6-g2cj, a critical Sdf_PathNode use-after-free. The lockfile has resolved that since moving to 25.11. Regenerating brings four packages in line with the lockfile (usd-core, urllib3, requests, marshmallow) and adds pytest, which became a project dependency after the last refresh. Querying OSV before and after, the advisory surface drops from 26 to 22 and no longer includes a critical. The uv export command is recorded in a header comment so the file can be regenerated reproducibly rather than drifting again. Signed-off-by: Dillon Bailey <dillonb@nvidia.com> Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
erslavin
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
requirements.txtwas last refreshed for v1.5.1 (December 2025), whileuv.lockhas since moved to v1.6.2. Nothing in the repo readsrequirements.txt— both CI jobs install withuv sync— so the drift went unnoticed. Dependency scanners still treat it as a manifest, though, and report vulnerabilities against versions the project no longer installs.Most notably it advertised
usd-core==25.5, which carries GHSA-58p5-r2f6-g2cj, a criticalSdf_PathNodeuse-after-free. The lockfile resolved that when it moved to 25.11.Changes
Regenerated from
uv.lock, bringing four packages back in line and addingpytest, which became a project dependency after the last refresh:usd-coreurllib3requestsmarshmallowPlus
pytest==9.0.2,pluggy==1.6.0,iniconfig==2.3.0. Nothing removed.The
uv exportcommand is now recorded in a header comment so the file can be regenerated reproducibly instead of drifting again.Verification
pytestadvisory that was previously invisible becausepytestwas missing from the file entirely, and aurllib3advisory specific to the 2.6.x line —urllib3still nets 4 → 2 overall.uv exportcommand reproduces the file byte-for-byte.No Sphinx build or test run was performed:
requirements.txtis referenced nowhere outside a descriptive line inAGENTS.md, and CI installs from the lockfile, so this file cannot affect the build.Worth discussing
This fixes the symptom. The file drifted because nothing consumes it and there was no documented way to regenerate it — the header comment helps, but it will drift again by the next release unless the export is wired into the release process. Given
uv.lockis the real source of truth, removingrequirements.txtaltogether may be the better long-term answer. Happy to follow up either way.🤖 Generated with Claude Code