Skip to content

Fix hosted scan not reading the Pipfile (#333) #253

Fix hosted scan not reading the Pipfile (#333)

Fix hosted scan not reading the Pipfile (#333) #253

name: Poetry patch compatibility
# Native Poetry installer matrix: builds the CLI once per OS, bootstraps each
# pinned Poetry release with uv, and runs `scripts/backtest-poetry.py` —
# hosted, vendored and agent mode against the public production patch,
# verifying the INSTALLED bytes, lock stability, rollback and the
# manifest-less VEX checks. No Socket API token is needed. POSIX only: the
# harness uses `bin/poetry` venv paths.
#
# The hermetic (wiremock) real-Poetry capstone (the `poetry::` module of
# the `e2e_vex_build` test binary) runs in ci.yml's `e2e` matrix; this
# workflow is the production-service, every-release twin.
on:
pull_request:
paths:
- '.github/actions/upload-artifact/**'
- '.github/actions/pin-socket-hosts/**'
- 'scripts/pin-socket-hosts.py'
- '.github/workflows/poetry-compatibility.yml'
- 'scripts/backtest-poetry.py'
- 'crates/socket-patch-core/src/utils/poetry_lock.rs'
- 'crates/socket-patch-core/src/patch/redirect/**'
- 'crates/socket-patch-core/src/vendor/pypi*.rs'
- 'crates/socket-patch-core/src/vex/discover/pypi_locks.rs'
- 'crates/socket-patch-cli/src/commands/scan/**'
- 'crates/socket-patch-cli/src/commands/vex.rs'
- 'crates/socket-patch-cli/src/commands/vex_sources.rs'
- 'crates/socket-patch-cli/src/commands/rollback.rs'
push:
branches: [main]
paths:
- 'scripts/backtest-poetry.py'
- '.github/actions/pin-socket-hosts/**'
- 'scripts/pin-socket-hosts.py'
- 'crates/socket-patch-core/src/utils/poetry_lock.rs'
- 'crates/socket-patch-core/src/patch/redirect/**'
- 'crates/socket-patch-core/src/vendor/pypi*.rs'
- 'crates/socket-patch-core/src/vex/discover/pypi_locks.rs'
workflow_dispatch:
permissions:
contents: read
concurrency:
group: poetry-compat-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
SOCKET_NO_CONFIG: '1'
SOCKET_NO_UPDATE_CHECK: '1'
jobs:
build:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
with:
key: poetry-compat
save-if: ${{ github.ref == 'refs/heads/main' }}
- run: cargo build --locked -p socket-patch-cli
- uses: ./.github/actions/upload-artifact
with:
name: poetry-cli-${{ matrix.os }}
path: target/debug/socket-patch
if-no-files-found: error
retention-days: 7
native:
needs: build
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
poetry: ['1.0.10', '1.1.15', '1.2.2', '1.3.2', '1.4.2', '1.5.1', '1.6.1', '1.7.1', '1.8.5', '2.0.1', '2.1.4', '2.2.1', '2.3.4', '2.4.3']
runs-on: ${{ matrix.os }}
timeout-minutes: 45
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: poetry-cli-${{ matrix.os }}*
merge-multiple: true
path: native-cli
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: '3.12'
- name: Pin the production patch hosts (macOS)
# The hosted macOS resolver intermittently loses patch.socket.dev for
# minutes (EAI_NONAME) while the service is up; see the action.
uses: ./.github/actions/pin-socket-hosts
# uv bootstraps every pinned Poetry release (and its interpreter)
# itself; pinning uv keeps the bootstrap reproducible.
- run: python -m pip install uv==0.11.19
- name: Exercise the native Poetry installers
shell: bash
env:
POETRY_VERSION: ${{ matrix.poetry }}
run: |
chmod +x native-cli/socket-patch
python3 scripts/backtest-poetry.py \
--cli native-cli/socket-patch \
--cli-revision "$GITHUB_SHA" \
--output native-poetry \
--versions "$POETRY_VERSION" \
--modes hosted vendored agent \
--shapes direct populated crlf \
--jobs 3
- uses: ./.github/actions/upload-artifact
if: always()
with:
name: poetry-results-${{ matrix.os }}-${{ matrix.poetry }}
path: |
native-poetry/summary.json
native-poetry/summary.md
native-poetry/captures/**/*.log
retention-days: 14