Skip to content

Commit 9e0aaea

Browse files
vvillait88claude
andauthored
Block prereleases, refresh the lock (#79)
## Summary Adds `prerelease = "disallow"` under `[tool.uv]` and refreshes the lock (lefthook 2.1.11). python-commerce has carried this guard since the sweep that added it; the rest of the fleet did not, which is backwards. The registry entry behind it says to check the whole fleet rather than the repo in front of you, because what it guards against is an unbounded transitive requirement rather than a particular package: an unbounded requirement lets a routine refresh resolve a beta and drag a subtree with it, and the suite passes either way, so nothing reports it. That is how python-commerce once resolved `web3` 8.0.0b3 through three unbounded parents. Every `uv.lock` in the workspace was swept for `a`/`b`/`rc` versions before writing this, enumerated with `find` rather than from memory since core holds three Python projects the JS tooling cannot see. All five are clean today, so this is a guard against the next refresh, not a fix for a live problem. The same guard is going into core's three projects in that repo's own PR. ## Type of change - [x] Docs, tests, or internal maintenance only ## Public API None. No exported symbol, signature, or wire format changed. **No version bump, deliberately.** The runbook releases only where a consumer must act, and a lockfile plus a resolver setting reaches nobody: the published wheel ships neither. ## Test plan Full gate set locally: `ruff check`, `ruff format --check`, `ty check`, `vulture` (run the way CI runs it, with the whitelist argument), and `pytest` (183 passed, 8 skipped, 100% coverage against a 95% floor). Exit codes read directly rather than off the tail of a pipe. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [ ] Docs and README examples updated if the public surface changed (the public surface did not change) - [x] No secrets, credentials, or personal data in the diff or the tests Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent b107ff2 commit 9e0aaea

2 files changed

Lines changed: 16 additions & 7 deletions

File tree

‎pyproject.toml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,3 +56,9 @@ include = ["agentscore"]
5656

5757
[tool.uv]
5858
required-version = ">=0.11.0"
59+
# An unbounded transitive requirement lets a routine refresh resolve a BETA and
60+
# drag a subtree with it, and the tests pass either way, so nothing reports it.
61+
# That is how python-commerce once resolved web3 8.0.0b3 through three
62+
# unbounded parents. Blocking prereleases outright beats pinning whichever
63+
# package surfaced last, since the same shape exists on several transitives.
64+
prerelease = "disallow"

‎uv.lock‎

Lines changed: 10 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)