Skip to content

Release 0.4.1 - #35

Merged
yudelevi merged 4 commits into
mainfrom
development
Sep 24, 2026
Merged

yudelevi merged 4 commits into
mainfrom
development

Conversation

@yudelevi

@yudelevi yudelevi commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Hotfix for discolike-cli 0.4.0 (yanked on PyPI): every command crashed in a fresh install with ImportError on typer._click.exceptions.Abort under Typer 0.27. Full notes in CHANGELOG.md under 0.4.1.

  • CLI imports the public typer.Abort; typer>=0.26.1,<0.28.
  • discolike[cli] extra pinned to discolike-cli==0.4.1.
  • New test-resolution CI job tests the pyproject ranges at highest and lowest-direct resolution plus a built-wheel smoke, not just uv.lock.

RetriggerConfidence Score: 4/5

The hotfix appears safe to merge, with a non-blocking recommendation to pin the newly added GitHub Actions references to immutable commits.

Fix All in Claude CodeFindings

  1. P2 Security Mutable Actions Run in CI ▶
Fix with agent prompt
### Issue 1
.github/workflows/ci.yml:41-42
The new resolution job uses mutable major-version tags for `actions/checkout` and `astral-sh/setup-uv`. If either upstream tag is repointed or compromised, pull-request and push workflows will execute substituted code with read access to the repository. This is a non-blocking hardening concern; pin both actions to full commit SHAs while retaining version comments for maintainability.

**How this was verified:** Both mutable references execute before repository-controlled test commands on every pull-request and selected push run with read access to the repository.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

This hotfix releases both distributions as 0.4.1, switches the CLI to Typer’s public Abort export, constrains Typer to the compatible range, and expands CI coverage for fresh dependency resolution and built-wheel installation.

  • Updates SDK and CLI package metadata and dependency pins to 0.4.1.
  • Adjusts parser-error assertions for supported Typer formatting differences.
  • Adds highest and lowest-direct dependency-resolution coverage.
  • The added workflow should pin its external actions to immutable commit SHAs.

Reviews (1) · Last reviewed commit: "Merge pull request #34 from discolike/fi..."

yudelevi and others added 4 commits September 23, 2026 17:30
A fresh install of discolike-cli 0.4.0 fails on every command with
ImportError: cannot import name 'Abort' from 'typer._click.exceptions'.
Typer 0.27 moved Abort to typer.exceptions. CI never saw it because it
tests against uv.lock, which pins Typer 0.26.8, while the published
constraint (typer>=0.12) let users resolve 0.27.2.

Import the public typer.Abort instead. The remaining imports still
reach into Typer's vendored Click (typer._click), which only exists
from 0.26 and is private, so bound the dependency to >=0.26,<0.28
rather than let the next minor break installs the same way.
Every CI job installed exactly what uv.lock pins, so the Typer 0.27
break that shipped in 0.4.0 was invisible: users resolve fresh from
the pyproject ranges. The new test-resolution job runs the suite and a
wheel install at both ends of those ranges.

Running it locally found two more problems. Typer 0.26.0 drops the
env-var API key in auth status, so the floor is 0.26.1. Two entrypoint
tests pinned Typer's exact error wording, which 0.27 changed; they now
check the flag or argument name the envelope must carry.
discolike[cli]==0.4.1 required discolike-cli==0.4.0, which requires
discolike==0.4.0, so the extra could not be installed.
Fix CLI import crash on Typer 0.27, release 0.4.1
Comment thread .github/workflows/ci.yml
Comment on lines +41 to +42
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Mutable Actions Run in CI

The new resolution job uses mutable major-version tags for actions/checkout and astral-sh/setup-uv. If either upstream tag is repointed or compromised, pull-request and push workflows will execute substituted code with read access to the repository. This is a non-blocking hardening concern; pin both actions to full commit SHAs while retaining version comments for maintainability.

How this was verified: Both mutable references execute before repository-controlled test commands on every pull-request and selected push run with read access to the repository.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/ci.yml
Line: 41-42

Comment:
**Mutable Actions Run in CI**

The new resolution job uses mutable major-version tags for `actions/checkout` and `astral-sh/setup-uv`. If either upstream tag is repointed or compromised, pull-request and push workflows will execute substituted code with read access to the repository. This is a non-blocking hardening concern; pin both actions to full commit SHAs while retaining version comments for maintainability.

**How this was verified:** Both mutable references execute before repository-controlled test commands on every pull-request and selected push run with read access to the repository.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not in this hotfix: every workflow here (ci, contract, publish) uses the same major tags, so pinning only the new job would be inconsistent. SHA-pinning all workflows is a separate change.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That’s fair. Since ci, contract, and publish all currently use the same major-version action tags, pinning only the new resolution job would create inconsistent hardening rather than address the repository-wide risk. I’ll treat this as out of scope for the 0.4.1 hotfix; SHA-pinning all workflows is better handled in a separate change.

@yudelevi
yudelevi merged commit 64ed3e2 into main Sep 24, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant