Skip to content

fix: stop setting UV_PYTHON for the caller's job - #89

Open
lhoupert wants to merge 2 commits into
mainfrom
fix/uv-python-leak
Open

lhoupert wants to merge 2 commits into
mainfrom
fix/uv-python-leak

Conversation

@lhoupert

@lhoupert lhoupert commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

The action's setup-uv step set python-version: '3.13', which exports UV_PYTHON=3.13 for the rest of the caller's job: uv export failed for projects with requires-python < 3.13, and the caller's later uv steps ran on Python 3.13. The audit step now passes --python 3.13 to its own uv run instead. The clean integration fixtures also stop pinning versions and committing lockfiles, so a new advisory no longer turns "Validate results" red with no code change; the deliberately vulnerable fixtures stay pinned.

For reviewers: later steps in the caller's job no longer get UV_PYTHON=3.13, and when uv export re-resolves (no uv.lock, or a stale one) it now uses the project's own Python. That may download one on hosted runners, and offline with downloads disabled it fails if no matching interpreter exists, the same constraint as forcing 3.13 before.

Author attestation

  • I am a human, these are my changes, and I have reviewed and understood every change and can explain why each is correct.

AI-assisted: Claude Code wrote the changes and ran the local checks: pytest, mypy, pre-commit, end-to-end runs of the audit step against v1.0.0 and a replay of the integration matrix.

lhoupert and others added 2 commits October 6, 2026 21:42
setup-uv's `python-version: '3.13'` exports UV_PYTHON=3.13 for the rest
of the caller's job. It overrode their .python-version and
requires-python: `uv export` failed for projects with
requires-python < 3.13, and their later `uv run`/`uv sync` steps got
Python 3.13. The audit step now passes `--python 3.13` to its own
`uv run` instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Clean fixtures pinned exact versions, so every new advisory against a pin
turned "Validate results" red with no code change. Cases 01, 02 and 11
now use `>=`, and cases 06 and 09 no longer commit uv.lock and
Pipfile.lock: CI generates them before the action, as for 04, 07 and 10.
The deliberately vulnerable cases (03, 05, 08) stay pinned, and the
validation checks are unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ All test workflows behaved as expected

13 passed, 0 failed

Test Name Expected Actual Bandit pip-audit Result
01 requirements · flat · clean success success — — ✅
02 requirements · src/ · bandit HIGH failure failure B105, B404, B602 — ✅
03 requirements · src/+scripts/ · bandit HIGH + pip-audit failure failure B105, B404, B602 click, cryptography, idna, requests, urllib3 ✅
04 uv · flat · clean success success — — ✅
05 uv · src/ · pip-audit vuln failure failure — click, idna, requests, urllib3 ✅
06 uv · src/+scripts/ · bandit MEDIUM failure failure B324, B506 — ✅
07 poetry · flat · clean success success — — ✅
08 poetry · src/ · bandit MEDIUM + pip-audit failure failure B105, B324 cryptography, idna, requests, urllib3 ✅
09 pipenv · flat · clean success success — — ✅
10 pipenv · src/+scripts/ · bandit HIGH failure failure B404, B602 — ✅
11 requirements · flat · clean (root working dir) success success — — ✅
12 uv · flat · bandit-only (no pip-audit) failure failure B404, B602 disabled ✅
14 uv · flat · low threshold (B101 assert) failure failure B101 disabled ✅

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant