Fix hosted scan not reading the Pipfile (#333) #253
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Poetry patch compatibility | |
| # Native Poetry installer matrix: builds the CLI once per OS, bootstraps each | |
| # pinned Poetry release with uv, and runs `scripts/backtest-poetry.py` — | |
| # hosted, vendored and agent mode against the public production patch, | |
| # verifying the INSTALLED bytes, lock stability, rollback and the | |
| # manifest-less VEX checks. No Socket API token is needed. POSIX only: the | |
| # harness uses `bin/poetry` venv paths. | |
| # | |
| # The hermetic (wiremock) real-Poetry capstone (the `poetry::` module of | |
| # the `e2e_vex_build` test binary) runs in ci.yml's `e2e` matrix; this | |
| # workflow is the production-service, every-release twin. | |
| on: | |
| pull_request: | |
| paths: | |
| - '.github/actions/upload-artifact/**' | |
| - '.github/actions/pin-socket-hosts/**' | |
| - 'scripts/pin-socket-hosts.py' | |
| - '.github/workflows/poetry-compatibility.yml' | |
| - 'scripts/backtest-poetry.py' | |
| - 'crates/socket-patch-core/src/utils/poetry_lock.rs' | |
| - 'crates/socket-patch-core/src/patch/redirect/**' | |
| - 'crates/socket-patch-core/src/vendor/pypi*.rs' | |
| - 'crates/socket-patch-core/src/vex/discover/pypi_locks.rs' | |
| - 'crates/socket-patch-cli/src/commands/scan/**' | |
| - 'crates/socket-patch-cli/src/commands/vex.rs' | |
| - 'crates/socket-patch-cli/src/commands/vex_sources.rs' | |
| - 'crates/socket-patch-cli/src/commands/rollback.rs' | |
| push: | |
| branches: [main] | |
| paths: | |
| - 'scripts/backtest-poetry.py' | |
| - '.github/actions/pin-socket-hosts/**' | |
| - 'scripts/pin-socket-hosts.py' | |
| - 'crates/socket-patch-core/src/utils/poetry_lock.rs' | |
| - 'crates/socket-patch-core/src/patch/redirect/**' | |
| - 'crates/socket-patch-core/src/vendor/pypi*.rs' | |
| - 'crates/socket-patch-core/src/vex/discover/pypi_locks.rs' | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: poetry-compat-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| SOCKET_NO_CONFIG: '1' | |
| SOCKET_NO_UPDATE_CHECK: '1' | |
| jobs: | |
| build: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest] | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| with: | |
| key: poetry-compat | |
| save-if: ${{ github.ref == 'refs/heads/main' }} | |
| - run: cargo build --locked -p socket-patch-cli | |
| - uses: ./.github/actions/upload-artifact | |
| with: | |
| name: poetry-cli-${{ matrix.os }} | |
| path: target/debug/socket-patch | |
| if-no-files-found: error | |
| retention-days: 7 | |
| native: | |
| needs: build | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest] | |
| poetry: ['1.0.10', '1.1.15', '1.2.2', '1.3.2', '1.4.2', '1.5.1', '1.6.1', '1.7.1', '1.8.5', '2.0.1', '2.1.4', '2.2.1', '2.3.4', '2.4.3'] | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: 45 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: poetry-cli-${{ matrix.os }}* | |
| merge-multiple: true | |
| path: native-cli | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Pin the production patch hosts (macOS) | |
| # The hosted macOS resolver intermittently loses patch.socket.dev for | |
| # minutes (EAI_NONAME) while the service is up; see the action. | |
| uses: ./.github/actions/pin-socket-hosts | |
| # uv bootstraps every pinned Poetry release (and its interpreter) | |
| # itself; pinning uv keeps the bootstrap reproducible. | |
| - run: python -m pip install uv==0.11.19 | |
| - name: Exercise the native Poetry installers | |
| shell: bash | |
| env: | |
| POETRY_VERSION: ${{ matrix.poetry }} | |
| run: | | |
| chmod +x native-cli/socket-patch | |
| python3 scripts/backtest-poetry.py \ | |
| --cli native-cli/socket-patch \ | |
| --cli-revision "$GITHUB_SHA" \ | |
| --output native-poetry \ | |
| --versions "$POETRY_VERSION" \ | |
| --modes hosted vendored agent \ | |
| --shapes direct populated crlf \ | |
| --jobs 3 | |
| - uses: ./.github/actions/upload-artifact | |
| if: always() | |
| with: | |
| name: poetry-results-${{ matrix.os }}-${{ matrix.poetry }} | |
| path: | | |
| native-poetry/summary.json | |
| native-poetry/summary.md | |
| native-poetry/captures/**/*.log | |
| retention-days: 14 |