fix: install the action and the pre-commit hook from source, not from an unpublished PyPI name - #197
Merged
Merged
Conversation
… an unpublished PyPI name Both entry points named `agentcost-py` as a registry install, but that distribution does not exist on PyPI, so neither could install anything: $ pre-commit install ... Installing environment for agentcost ... ERROR: Could not find a version that satisfies the requirement agentcost-py ERROR: No matching distribution found for agentcost-py The composite action died on the same line before it reached a single one of its own steps, so anyone using the repository as an Action got no analysis at all -- a failure with no output and no hint that it was an install problem. The name is not the issue and cannot be changed: `agentcost` on PyPI belongs to an unrelated project (github.com/agentcost-ai/agentcost-sdk), which is why this distribution ships under `agentcost-py`. Only the resolution is wrong. Both files now install a PEP 508 direct reference against this repository: pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git" The `name @` prefix is kept rather than the bare clone URL because pip then refuses the install if the distribution is ever renamed, instead of silently installing whatever the clone happens to provide. Verified in a clean virtualenv created outside the repository: $ python -m pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git" Resolved https://github.com/yunaremaia/agentcost.git to commit d951693 Successfully built agentcost_py-0.3.0-py3-none-any.whl Successfully installed agentcost-py-0.3.0 click-8.5.0 markdown-it-py-4.2.0 mdurl-0.1.2 pygments-2.21.0 rich-15.0.0 $ agentcost --version agentcost, version 0.3.0 The installed distribution records the provenance it claims -- `direct_url.json` holds the same URL and commit id -- and the console script is `agentcost`, not the distribution name, so `entry: agentcost today` in the hook and the `agentcost` invocation in the action keep working unchanged. tests/test_distribution_name.py gains the guard this fix was missing. The existing checks read the distribution *name* off the command line, and a name is satisfied just as well by a URL pointing at someone else's repository as by the right one -- so a foreign target would have passed every assertion while pre-commit installed a foreign package. `install_urls()` extracts the clone target out of a `name @ url` reference (splitting on whitespace leaves the `@` glued to the name) and both files are now required to name a source at all and to name *this* repository, with the expected URL read from `[project.urls] Homepage` rather than hardcoded. Run against the un-fixed action.yml and .pre-commit-hooks.yaml with the test file kept in place, the new guards report 2 failed, 15 passed; with the fix they report 17 passed. Full suite: 303 passed, 1 skipped. `ruff check src tests` passes. The action and the hook now track the default branch instead of a pinned release, and no longer consume a PyPI release. That is the intended trade while the distribution is unpublished; publishing to PyPI should revert both lines and relax the source assertion in the same change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Failure mode
The composite Action and the pre-commit hook both installed
agentcost-pyas a registry install, but that distribution has never been published to PyPI. Neither entry point could install anything:The Action failed on the same line before reaching any of its own steps, so using the repository as an Action produced no analysis, no output, and no hint that the problem was the install step.
The distribution name is not the defect and cannot be changed:
agentcoston PyPI belongs to an unrelated project (github.com/agentcost-ai/agentcost-sdk), which is why this distribution ships asagentcost-py. Only the resolution was wrong.Fix
Both files install a PEP 508 direct reference against this repository:
pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git"The
name @prefix is kept instead of the bare clone URL so pip refuses the install if the distribution is ever renamed, rather than silently installing whatever the clone provides.Related issue
Fixes #
Type of change
The breaking-change half is noted under Notes: the Action and the hook now track the default branch instead of a pinned PyPI release.
Testing
Clean virtualenv created outside the repository (
/root/.hermes/cache/scratch/agentcost-clean, Python 3.14.7, pip 26.2.1):The console script is
agentcost, not the distribution name, soentry: agentcost todayin the hook and theagentcostinvocation in the Action are unaffected. The installed distribution records the provenance it claims —direct_url.jsonholds the same URL and commit id (d9516932a9dbdc8cb6c5b173ca62bb82b1a07d10).Test coverage and the red/green evidence
tests/test_distribution_name.pygains the guard this fix was missing. The existing checks read the distribution name off the command line, and a name is satisfied just as well by a URL pointing at someone else's repository as by the right one — a foreign target would pass every existing assertion while pre-commit installed a foreign package.install_urls()extracts the clone target from aname @ urlreference (splitting on whitespace alone leaves the@glued to the name), and both files must now name a source at all and name this repository, with the expected URL read from[project.urls] Homepagerather than hardcoded.action.yml+.pre-commit-hooks.yaml, new tests in place (git stashof the two non-test files only)The two failures are
test_composite_action_installs_the_distributionandtest_pre_commit_hook_installs_from_this_repository.test_vcs_install_urls_are_extracted_not_the_bare_schemeis the control that feeds the extractor both a correct and a foreign target, so the guard is shown to be able to fail.Full suite: 303 passed, 1 skipped
ruff check src tests: All checks passedBoth YAML files parse, and the hook's
additional_dependenciesresolves to a single valid requirement string.Tests added/updated
Manual testing performed
Checklist
Notes
Breaking change / tradeoff. Installing from git means the Action and the hook now track the repository's default branch instead of a pinned release, and no longer consume a PyPI release. That is the intended trade while the distribution is unpublished.
Follow-up when a PyPI release actually exists: revert both install lines to a registry install and relax the "must name a source" half of both assertions in the same change. The comments at both call sites say so.
On the suite count.
tests/test_init_command.py::TestInitCommand::test_init_projectfails in a narrow terminal becauserichwraps the config path mid-string. It is unrelated to this change and fails identically on pristineHEAD; it passes withCOLUMNS=200. All counts above were taken at a normal terminal width.