Skip to content

fix: install the action and the pre-commit hook from source, not from an unpublished PyPI name - #197

Merged
yunaremaia merged 1 commit into
mainfrom
fix/action-and-hook-install-resolve
Oct 4, 2026
Merged

yunaremaia merged 1 commit into
mainfrom
fix/action-and-hook-install-resolve

Conversation

@yunaremaia

Copy link
Copy Markdown
Owner

Description

Failure mode

The composite Action and the pre-commit hook both installed agentcost-py as a registry install, but that distribution has never been published to PyPI. Neither entry point could install anything:

$ pre-commit install
... Installing environment for agentcost ...
ERROR: Could not find a version that satisfies the requirement agentcost-py
ERROR: No matching distribution found for agentcost-py

The Action failed on the same line before reaching any of its own steps, so using the repository as an Action produced no analysis, no output, and no hint that the problem was the install step.

The distribution name is not the defect and cannot be changed: agentcost on PyPI belongs to an unrelated project (github.com/agentcost-ai/agentcost-sdk), which is why this distribution ships as agentcost-py. Only the resolution was wrong.

Fix

Both files install a PEP 508 direct reference against this repository:

pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git"

The name @ prefix is kept instead of the bare clone URL so pip refuses the install if the distribution is ever renamed, rather than silently installing whatever the clone provides.

Related issue

Fixes #

Type of change

  • Bug fix (non-breaking change that fixes an issue)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • New feature (non-breaking change that adds functionality)
  • Documentation update

The breaking-change half is noted under Notes: the Action and the hook now track the default branch instead of a pinned PyPI release.

Testing

Clean virtualenv created outside the repository (/root/.hermes/cache/scratch/agentcost-clean, Python 3.14.7, pip 26.2.1):

$ python -m pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git"
Resolved https://github.com/yunaremaia/agentcost.git to commit d951693
Successfully built agentcost_py-0.3.0-py3-none-any.whl
Successfully installed agentcost-py-0.3.0 click-8.5.0 markdown-it-py-4.2.0 mdurl-0.1.2 pygments-2.21.0 rich-15.0.0

$ agentcost --version
agentcost, version 0.3.0

$ agentcost --help
Usage: agentcost [OPTIONS] COMMAND [ARGS]...

The console script is agentcost, not the distribution name, so entry: agentcost today in the hook and the agentcost invocation in the Action are unaffected. The installed distribution records the provenance it claims — direct_url.json holds the same URL and commit id (d9516932a9dbdc8cb6c5b173ca62bb82b1a07d10).

Test coverage and the red/green evidence

tests/test_distribution_name.py gains the guard this fix was missing. The existing checks read the distribution name off the command line, and a name is satisfied just as well by a URL pointing at someone else's repository as by the right one — a foreign target would pass every existing assertion while pre-commit installed a foreign package. install_urls() extracts the clone target from a name @ url reference (splitting on whitespace alone leaves the @ glued to the name), and both files must now name a source at all and name this repository, with the expected URL read from [project.urls] Homepage rather than hardcoded.

State Result
Un-fixed action.yml + .pre-commit-hooks.yaml, new tests in place (git stash of the two non-test files only) 2 failed, 15 passed
With this fix 17 passed

The two failures are test_composite_action_installs_the_distribution and test_pre_commit_hook_installs_from_this_repository. test_vcs_install_urls_are_extracted_not_the_bare_scheme is the control that feeds the extractor both a correct and a foreign target, so the guard is shown to be able to fail.

  • Full suite: 303 passed, 1 skipped

  • ruff check src tests: All checks passed

  • Both YAML files parse, and the hook's additional_dependencies resolves to a single valid requirement string.

  • Tests added/updated

  • Manual testing performed

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Documentation updated (if needed)
  • CI passes

Notes

Breaking change / tradeoff. Installing from git means the Action and the hook now track the repository's default branch instead of a pinned release, and no longer consume a PyPI release. That is the intended trade while the distribution is unpublished.

Follow-up when a PyPI release actually exists: revert both install lines to a registry install and relax the "must name a source" half of both assertions in the same change. The comments at both call sites say so.

On the suite count. tests/test_init_command.py::TestInitCommand::test_init_project fails in a narrow terminal because rich wraps the config path mid-string. It is unrelated to this change and fails identically on pristine HEAD; it passes with COLUMNS=200. All counts above were taken at a normal terminal width.

… an unpublished PyPI name

Both entry points named `agentcost-py` as a registry install, but that
distribution does not exist on PyPI, so neither could install anything:

  $ pre-commit install
  ... Installing environment for agentcost ...
  ERROR: Could not find a version that satisfies the requirement agentcost-py
  ERROR: No matching distribution found for agentcost-py

The composite action died on the same line before it reached a single one of
its own steps, so anyone using the repository as an Action got no analysis at
all -- a failure with no output and no hint that it was an install problem.

The name is not the issue and cannot be changed: `agentcost` on PyPI belongs
to an unrelated project (github.com/agentcost-ai/agentcost-sdk), which is why
this distribution ships under `agentcost-py`. Only the resolution is wrong.
Both files now install a PEP 508 direct reference against this repository:

  pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git"

The `name @` prefix is kept rather than the bare clone URL because pip then
refuses the install if the distribution is ever renamed, instead of silently
installing whatever the clone happens to provide.

Verified in a clean virtualenv created outside the repository:

  $ python -m pip install "agentcost-py @ git+https://github.com/yunaremaia/agentcost.git"
  Resolved https://github.com/yunaremaia/agentcost.git to commit d951693
  Successfully built agentcost_py-0.3.0-py3-none-any.whl
  Successfully installed agentcost-py-0.3.0 click-8.5.0 markdown-it-py-4.2.0
                         mdurl-0.1.2 pygments-2.21.0 rich-15.0.0
  $ agentcost --version
  agentcost, version 0.3.0

The installed distribution records the provenance it claims --
`direct_url.json` holds the same URL and commit id -- and the console script
is `agentcost`, not the distribution name, so `entry: agentcost today` in the
hook and the `agentcost` invocation in the action keep working unchanged.

tests/test_distribution_name.py gains the guard this fix was missing. The
existing checks read the distribution *name* off the command line, and a
name is satisfied just as well by a URL pointing at someone else's
repository as by the right one -- so a foreign target would have passed every
assertion while pre-commit installed a foreign package. `install_urls()`
extracts the clone target out of a `name @ url` reference (splitting on
whitespace leaves the `@` glued to the name) and both files are now required
to name a source at all and to name *this* repository, with the expected
URL read from `[project.urls] Homepage` rather than hardcoded.

Run against the un-fixed action.yml and .pre-commit-hooks.yaml with the test
file kept in place, the new guards report 2 failed, 15 passed; with the fix
they report 17 passed. Full suite: 303 passed, 1 skipped. `ruff check src
tests` passes.

The action and the hook now track the default branch instead of a pinned
release, and no longer consume a PyPI release. That is the intended trade
while the distribution is unpublished; publishing to PyPI should revert both
lines and relax the source assertion in the same change.
@yunaremaia
yunaremaia merged commit b09caee into main Oct 4, 2026
5 checks passed
@yunaremaia
yunaremaia deleted the fix/action-and-hook-install-resolve branch October 4, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant