Release 0.4.1 - #35
Conversation
A fresh install of discolike-cli 0.4.0 fails on every command with ImportError: cannot import name 'Abort' from 'typer._click.exceptions'. Typer 0.27 moved Abort to typer.exceptions. CI never saw it because it tests against uv.lock, which pins Typer 0.26.8, while the published constraint (typer>=0.12) let users resolve 0.27.2. Import the public typer.Abort instead. The remaining imports still reach into Typer's vendored Click (typer._click), which only exists from 0.26 and is private, so bound the dependency to >=0.26,<0.28 rather than let the next minor break installs the same way.
Every CI job installed exactly what uv.lock pins, so the Typer 0.27 break that shipped in 0.4.0 was invisible: users resolve fresh from the pyproject ranges. The new test-resolution job runs the suite and a wheel install at both ends of those ranges. Running it locally found two more problems. Typer 0.26.0 drops the env-var API key in auth status, so the floor is 0.26.1. Two entrypoint tests pinned Typer's exact error wording, which 0.27 changed; they now check the flag or argument name the envelope must carry.
discolike[cli]==0.4.1 required discolike-cli==0.4.0, which requires discolike==0.4.0, so the extra could not be installed.
Fix CLI import crash on Typer 0.27, release 0.4.1
| - uses: actions/checkout@v4 | ||
| - uses: astral-sh/setup-uv@v5 |
There was a problem hiding this comment.
The new resolution job uses mutable major-version tags for actions/checkout and astral-sh/setup-uv. If either upstream tag is repointed or compromised, pull-request and push workflows will execute substituted code with read access to the repository. This is a non-blocking hardening concern; pin both actions to full commit SHAs while retaining version comments for maintainability.
How this was verified: Both mutable references execute before repository-controlled test commands on every pull-request and selected push run with read access to the repository.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/ci.yml
Line: 41-42
Comment:
**Mutable Actions Run in CI**
The new resolution job uses mutable major-version tags for `actions/checkout` and `astral-sh/setup-uv`. If either upstream tag is repointed or compromised, pull-request and push workflows will execute substituted code with read access to the repository. This is a non-blocking hardening concern; pin both actions to full commit SHAs while retaining version comments for maintainability.
**How this was verified:** Both mutable references execute before repository-controlled test commands on every pull-request and selected push run with read access to the repository.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.There was a problem hiding this comment.
Not in this hotfix: every workflow here (ci, contract, publish) uses the same major tags, so pinning only the new job would be inconsistent. SHA-pinning all workflows is a separate change.
There was a problem hiding this comment.
That’s fair. Since ci, contract, and publish all currently use the same major-version action tags, pinning only the new resolution job would create inconsistent hardening rather than address the repository-wide risk. I’ll treat this as out of scope for the 0.4.1 hotfix; SHA-pinning all workflows is better handled in a separate change.
Hotfix for discolike-cli 0.4.0 (yanked on PyPI): every command crashed in a fresh install with ImportError on
typer._click.exceptions.Abortunder Typer 0.27. Full notes in CHANGELOG.md under 0.4.1.typer.Abort;typer>=0.26.1,<0.28.discolike[cli]extra pinned todiscolike-cli==0.4.1.test-resolutionCI job tests the pyproject ranges at highest and lowest-direct resolution plus a built-wheel smoke, not just uv.lock.The hotfix appears safe to merge, with a non-blocking recommendation to pin the newly added GitHub Actions references to immutable commits.
Fix with agent prompt
Summary
This hotfix releases both distributions as 0.4.1, switches the CLI to Typer’s public
Abortexport, constrains Typer to the compatible range, and expands CI coverage for fresh dependency resolution and built-wheel installation.Reviews (1) · Last reviewed commit: "Merge pull request #34 from discolike/fi..."