Repository navigation
Releases: altana-ai/pex
Release list
v2.98.3-altana.1: PEP-691 auth fix for lock creation
Patched build of Pex v2.98.3 carrying the fix for
pex-tool/pex#3224
(upstream PR: pex-tool/pex#3225).
Branch: pep-691-endpoint-auth-2.98.3 (the v2.98.3 tag + the three fix commits).
Supersedes v2.98.2-altana.1:
newer upstream base, and the fix is now the reviewed/trimmed form — the scheme-guarded auth
handlers from the earlier build were dropped after instrumentation proved they never execute
(preemptive Basic authentication avoids the challenge entirely). Functionally equivalent, smaller
delta from upstream.
What's patched
Without the fix, pex3 lock create against an authenticated PEP-691 index (AWS CodeArtifact since
its July 2026 JSON simple API rollout) cannot authenticate its PEP-691 hash lookups, silently
falls back to downloading every artifact of every locked project, and builds sdist metadata along
the way — failing lock generation on any sdist that cannot build on the lock host
(psycopg2-binary needs pg_config, older setup.py files import pkg_resources which
setuptools >= 81 removed, adbc-driver-postgresql needs a native library, ...).
Two changes, both required:
Lockerstrips Pip-redacted credentials (https://user:****@...) from the PEP-691 endpoints it
scrapes from the Pip log.URLFetchersends known machine-scoped credentials preemptively as a BasicAuthorization
header, which avoids provoking CodeArtifact's401 WWW-Authenticate: Bearerchallenge that the
Python stdlib auth handlers cannot process.
Validation
Against a live AWS CodeArtifact repository, cold PEX_ROOT (empty fingerprint cache, so the
authenticated JSON API requests must genuinely succeed):
| requirement | exit | fingerprint downloads | artifacts locked |
|---|---|---|---|
psycopg2-binary==2.9.12 |
0 | 0 | 12 |
ddtrace==3.19.1 |
0 | 0 | 33 |
No Failed to fetch project metadata warnings, no Bearer scheme errors, no silent download
fallback. Recorded hashes are sha256 and match the index's advertised hashes.sha256 exactly.
Upstream format, lint-check, typecheck (601 files, Python 2.7 + 3.5 modes) and the touched
test suites all pass on this base.
Assets
pex— the Pex PEX (py2.py3-none-anyzipapp; the same file serves every platform: linux
arm64/x86_64, macOS arm64/x86_64)pex.sha256— checksum
sha256: 8a482d87fcb3c3ea321ff7e85c00afdf78cab6409dc544cd3d8fa40f3d8d6474
size: 4618211 bytes
Pants usage
Requires a Pants release whose supported Pex range includes 2.98.3 (e.g. Pants 2.33, which
requires pex>=2.97.1).
[pex-cli]
version = "v2.98.3"
known_versions = [
"v2.98.3|linux_arm64|8a482d87fcb3c3ea321ff7e85c00afdf78cab6409dc544cd3d8fa40f3d8d6474|4618211|https://github.com/altana-ai/pex/releases/download/v2.98.3-altana.1/pex",
"v2.98.3|linux_x86_64|8a482d87fcb3c3ea321ff7e85c00afdf78cab6409dc544cd3d8fa40f3d8d6474|4618211|https://github.com/altana-ai/pex/releases/download/v2.98.3-altana.1/pex",
"v2.98.3|macos_arm64|8a482d87fcb3c3ea321ff7e85c00afdf78cab6409dc544cd3d8fa40f3d8d6474|4618211|https://github.com/altana-ai/pex/releases/download/v2.98.3-altana.1/pex",
"v2.98.3|macos_x86_64|8a482d87fcb3c3ea321ff7e85c00afdf78cab6409dc544cd3d8fa40f3d8d6474|4618211|https://github.com/altana-ai/pex/releases/download/v2.98.3-altana.1/pex",
]Remove the override once an upstream Pex release containing pex-tool#3225 ships and Pants pins
it.
v2.98.2-altana.1: PEP-691 auth fix for lock creation
Patched build of Pex v2.98.2 (latest upstream release) carrying the fix for
pex-tool/pex#3224
(upstream PR: pex-tool/pex#3225).
Branch: pep-691-endpoint-auth-2.98 (the v2.98.2 tag + the one fix commit).
What's patched
Without the fix, pex3 lock create against an authenticated PEP-691 index (AWS CodeArtifact
since its July 2026 JSON simple API rollout) downloads every artifact of every locked project to
fingerprint it and builds sdists along the way, failing lock generation on any sdist that cannot
build on the lock host (psycopg2-binary without pg_config, import pkg_resources under
setuptools>=81, etc.).
With the fix, artifact hashes come from authenticated PEP-691 JSON API requests: zero fingerprint
downloads, no sdist builds, and lockfile artifact sets + sha256s byte-identical to those produced
from PEP 503 HTML responses.
Assets
pex— the Pex PEX (py2.py3-none-anyzipapp; the same file serves every platform: linux
arm64/x86_64, macOS arm64/x86_64)pex.sha256— checksum
sha256: b3d9b496d05af7d21464c22d6aef4f8c3b11e20cc8cce8acb3c9c3e49324a33b
size: 4618120 bytes
⚠️ Pants compatibility
Do NOT use this build as the [pex-cli] override on Pants 2.30.0. Pex 2.9x changed
interpreter-discovery behavior in a way Pants 2.30.0 does not handle (fails during
Find interpreter for constraints before lock generation begins, independent of this patch).
For Pants 2.30.0 use
v2.66.0-altana.1 instead.
This build is for direct pex3 usage and for newer Pants versions whose pinned Pex is >= the
version where that discovery behavior is expected; re-validate before wiring it into Pants.
Remove all overrides once an upstream Pex release containing pex-tool#3225 ships and Pants
pins it.
v2.66.0-altana.1: PEP-691 auth fix for lock creation
Patched build of Pex v2.66.0 for Altana's Pants [pex-cli] tool override.
What's patched
Cherry-pick of the fix for pex-tool/pex#3224
(upstream PR: pex-tool/pex#3225) onto the v2.66.0
tag — the exact Pex version Pants 2.30.0 pins. Branch: pep-691-endpoint-auth-2.66.
Without the fix, pex3 lock create against an authenticated PEP-691 index (AWS CodeArtifact
since its July 2026 JSON simple API rollout) downloads every artifact of every locked project to
fingerprint it and builds sdists along the way, failing lock generation on any sdist that cannot
build on the lock host (psycopg2-binary without pg_config, import pkg_resources under
setuptools>=81, etc.).
With the fix, artifact hashes come from authenticated PEP-691 JSON API requests: zero fingerprint
downloads, no sdist builds, and lockfile artifact sets + sha256s byte-identical to those produced
from PEP 503 HTML responses.
Assets
pex— the Pex PEX (py2.py3-none-anyzipapp; the same file serves every platform)pex.sha256— checksum
sha256: 0d6e7f5c34e97075cddecc0a9eba306267bdb2a36cc7c1cd80d337077e301933
size: 4512999 bytes
Pants usage
[pex-cli]
version = "v2.66.0"
known_versions = [
"v2.66.0|linux_arm64|0d6e7f5c34e97075cddecc0a9eba306267bdb2a36cc7c1cd80d337077e301933|4512999|https://github.com/altana-ai/pex/releases/download/v2.66.0-altana.1/pex",
"v2.66.0|linux_x86_64|0d6e7f5c34e97075cddecc0a9eba306267bdb2a36cc7c1cd80d337077e301933|4512999|https://github.com/altana-ai/pex/releases/download/v2.66.0-altana.1/pex",
"v2.66.0|macos_arm64|0d6e7f5c34e97075cddecc0a9eba306267bdb2a36cc7c1cd80d337077e301933|4512999|https://github.com/altana-ai/pex/releases/download/v2.66.0-altana.1/pex",
]Remove the override once an upstream Pex release containing pex-tool#3225 ships and Pants
pins it.