Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 9 additions & 5 deletions .github/workflows/ui.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,9 +73,9 @@ jobs:
$uvVersion = (& uv --version).Trim()
if (
$LASTEXITCODE -ne 0 -or
$uvVersion -notmatch '^uv 0\.11\.15(?:\s|$)'
$uvVersion -notmatch '^uv 0\.12\.1(?:\s|$)'
) {
throw "Expected the exact lock-pinned uv 0.11.15 build."
throw "Expected the exact lock-pinned uv 0.12.1 build."
}
- name: Configure pinned Rust MSVC toolchain
shell: pwsh
Expand Down Expand Up @@ -139,7 +139,11 @@ jobs:
)
}
- name: Upload sanitized native smoke failure receipt
if: failure()
# The glob is only set once the smoke step runs. A failure BEFORE that
# leaves it empty, and this step then dies with "Input required and not
# supplied: path" -- which lands last in the log and buries the real
# error. Guard on the variable so an early failure reports itself.
if: failure() && env.DUMBMONEY_NATIVE_SMOKE_FAILURE_GLOB != ''
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: dumbmoney-native-smoke-failure-${{ github.run_id }}-${{ github.run_attempt }}
Expand Down Expand Up @@ -186,9 +190,9 @@ jobs:
$uvVersion = (& uv --version).Trim()
if (
$LASTEXITCODE -ne 0 -or
$uvVersion -notmatch '^uv 0\.11\.15(?:\s|$)'
$uvVersion -notmatch '^uv 0\.12\.1(?:\s|$)'
) {
throw "Expected the exact lock-pinned uv 0.11.15 build."
throw "Expected the exact lock-pinned uv 0.12.1 build."
}
- name: Configure pinned Rust MSVC toolchain
shell: pwsh
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ validation = [
"pytest==9.1.1",
"ruff==0.16.1",
"setuptools==83.0.0",
"uv==0.11.15",
"uv==0.12.1",
]

[tool.setuptools]
Expand Down
40 changes: 20 additions & 20 deletions requirements-validation.lock
Original file line number Diff line number Diff line change
Expand Up @@ -247,23 +247,23 @@ tomli-w==1.2.0 \
urllib3==2.7.0 \
--hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \
--hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897
uv==0.11.15 \
--hash=sha256:0ed920e896b2fd13a35031707e307e42fbb2681458b967440a17272d86d49137 \
--hash=sha256:40ff67e3f8e8a7533781a2e892a534975a93acb83ea35460e64e7b2bf2111774 \
--hash=sha256:41d907611f3e6a13262807fd7f0a17849f76285ca80f536f6b3943732bdc6656 \
--hash=sha256:49dc6ed70bff00937384f96cdc4b1a4742d18e5504ec2c4a1214dba2dee5687a \
--hash=sha256:4f39426a13dee24897aed60c4b98058c66f18bd983885ac5f4a54a04b24fbddf \
--hash=sha256:68c1e62d4b78578b90b833553286b65d6a7e327537716441068583ba652ec4f5 \
--hash=sha256:755f959ec6a2fd8ccb6ee76ad90ab759d2eb1f4797444078645dd1ee4bca92d6 \
--hash=sha256:83b04ab49514a0a761ffedb36a748ee81f87746671e72088e5f32c9585e5f1a9 \
--hash=sha256:8e2da3076761086a5b76869c3f38ef0509c836046ef41ddd19485dfd7271dca9 \
--hash=sha256:98edf1bdaf82447014852051d93e3ee95012509c567bf057fd117e6bdbd9a807 \
--hash=sha256:9accae33619a9166e5c48531deb455d672cfb89f9357a00975e669c76b0bd49f \
--hash=sha256:adb9a89352539fdd8f7cd5f9966cf9f94fc5b98e0ccdf5003a04123dc6423bec \
--hash=sha256:b6cae61f737be075b90be9e3f07d961072aed7019f4c9b8ed5c5d41c4d6cade3 \
--hash=sha256:be8f76d25bcf4c92bb384240ac1bf9aa7f51063d0bdeca4c9cf0ec3ed8b145e0 \
--hash=sha256:c0cf52cd6d50bb9e05e2d968f45f80761107e4cbc8d4a26d9758f9d8274aaec1 \
--hash=sha256:c6463a299ed7e6b5a800ed6f108af8e1588352629424133ddef7572b0e1e1118 \
--hash=sha256:cc3915ab291a1ecaf31de05f5d8bd70d09c66fe9911a53f70d9efa62ff0dbd8a \
--hash=sha256:e3b68f8bf1a4568710f77e5bda9182ce7682811d89a8e7468c22460e032b234d \
--hash=sha256:f9f4fbbf4fe485522054f3c7496c6e8e932d6436e4200ff3daf718db0b7c7bd5
uv==0.12.1 \
--hash=sha256:04290ea4001dca31ac8a8324113a4930dccad69ce35dbf6eaae307d54880890d \
--hash=sha256:153ec0959a15397514438aefc1d7cd04235f335dd6bb53ea0f9e6e82c5a49f03 \
--hash=sha256:173ee216f17d89fc39f65339d311a53584fc7de4918d27c0f3c7edafabc6b54d \
--hash=sha256:1de49d9b04438f1ad2f41a1441dbbe19e230b94fca56d632818cfaed69e03bfc \
--hash=sha256:1e8fd95fe98768e29436ad57f9ef7b68dc294b7b9862ef63396af8b15ab85e6c \
--hash=sha256:27211df9b277f440dea438a4e525ba40250fb721ad39b8927eefc2d91f9aea15 \
--hash=sha256:29399e1e73b67ed24abe82bc971aa4eb8419c4de804784290f39cf681f0b51ce \
--hash=sha256:2e9b0b86e180abc5968b979c6e25203b32e85969abb5083ee1e8b88a5aa98a76 \
--hash=sha256:3bd5db002adc763aa8d277f5b44f8d6e3fd82d20f2e51225b0bbdae1badc7259 \
--hash=sha256:41b8fc2335f682312a1ca39a7b4abfd6af800992065c663582ca3e4d51cf9258 \
--hash=sha256:5bd04849dd5346517cc4e57b4b3aa0b01c67c423878260c04f5893a038fe25b6 \
--hash=sha256:6f7e72543264d2420ebb2ddc84696a751af2d6c5910046b7666589118f47292b \
--hash=sha256:71f86410264c69a3e8acd18171897dd8ab1a13350cf40f718e4def5db2b724be \
--hash=sha256:76d87de420213ca92fa403e87023c4c7c6956c6726c6b96d91c42cfe620173a3 \
--hash=sha256:9331dda0dc4990512c232f86e1d3a7b83c13f459777fcc2bd46030911b40eaaa \
--hash=sha256:b255ac23958e45f39f9c7a4cd65890df5ef46f539a3b14de03bd296bbba9cb60 \
--hash=sha256:bd02f2da212e6a983115dc64a6fc94e9256c2d60e056d6b669de0a6025aaec05 \
--hash=sha256:e35e0030480a8c3bf8ecd87ae4a6f6a224009e15e96a6fbb3634ac11ab75d582 \
--hash=sha256:ead7ad064f291a5df358c3ffa8ffab347a32bd5a75a6a068ca22254c2539a829
2 changes: 1 addition & 1 deletion scripts/validate_release_python.py
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@
"pytest": "9.1.1",
"ruff": "0.16.1",
"setuptools": "83.0.0",
"uv": "0.11.15",
"uv": "0.12.1",
}
VALIDATION_BOUNDARIES = {
"rustsec_advisory_scan": (
Expand Down
29 changes: 28 additions & 1 deletion tests/test_release_build_trust.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,27 @@
BUILD_SCRIPT = WORKSPACE / "scripts" / "Build-DumbMoneyDesktop.ps1"
UI_WORKFLOW = WORKSPACE / ".github" / "workflows" / "ui.yml"
DEPENDABOT = WORKSPACE / ".github" / "dependabot.yml"
VALIDATION_LOCK = WORKSPACE / "requirements-validation.lock"


def locked_uv_version() -> str:
"""Read the pinned uv version from the lock rather than restating it here.

Hard-coding it made this assertion one more site to remember: bumping uv
meant editing pyproject, uv.lock, requirements-validation.lock,
EXPECTED_VALIDATION_TOOLS, EXPECTED_TOOL_VERSIONS, the workflow regex, the
workflow throw message, and this test -- eight places, and this one failed
only after the other seven were already done.

Deriving it also makes the test STRONGER. It now fails when the workflow
and the lock disagree, which is the drift it exists to catch, rather than
when both correctly move off a literal written here.
"""

for line in VALIDATION_LOCK.read_text(encoding="utf-8").splitlines():
if line.startswith("uv=="):
return line.split("==", 1)[1].split()[0].rstrip("\\").strip()
raise AssertionError("requirements-validation.lock does not pin uv")


class NativeReleaseBuildTrustTests(unittest.TestCase):
Expand Down Expand Up @@ -265,8 +286,14 @@ def test_native_workflow_bootstraps_exact_lock_pinned_uv_before_builds(
"--requirement requirements-validation.lock",
job,
)
expected = locked_uv_version()
escaped = expected.replace(".", "\\.")
self.assertIn(
f"$uvVersion -notmatch '^uv {escaped}(?:\\s|$)'",
job,
)
self.assertIn(
"$uvVersion -notmatch '^uv 0\\.11\\.15(?:\\s|$)'",
f"Expected the exact lock-pinned uv {expected} build.",
job,
)
self.assertLess(
Expand Down
2 changes: 1 addition & 1 deletion tests/test_validation_dependency_lock.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
"pytest": "9.1.1",
"ruff": "0.16.1",
"setuptools": "83.0.0",
"uv": "0.11.15",
"uv": "0.12.1",
}


Expand Down
46 changes: 23 additions & 23 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.