Skip to content

fix: address Python CI pinning failures in Wave 1 sync PRs - #2006

Merged
stranske merged 2 commits into
mainfrom
fix/sync-pr-python-ci-pinning
May 5, 2026
Merged

fix: address Python CI pinning failures in Wave 1 sync PRs#2006
stranske merged 2 commits into
mainfrom
fix/sync-pr-python-ci-pinning

Conversation

@stranske

@stranske stranske commented May 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • fix scripts/sync_test_dependencies.py so stdlib imports from consumer tests are not reported as undeclared third-party dependencies
  • add a jwt -> PyJWT mapping so repos that already declare PyJWT satisfy tests importing jwt
  • keep the canonical script and consumer-template copy in sync, with regression coverage for the exact imports seen in Wave 1 sync PR logs

Root Cause

I read the Python CI logs end-to-end for:

The jobs were not failing on the pinned-tool guard itself. They failed when scripts/sync_test_dependencies.py --verify misclassified stdlib imports as undeclared dependencies:

  • Travel: html, http, secrets, plus jwt missing the PyJWT package-name mapping
  • trip-planner: email, http

The later tomlkit is required... message is a secondary effect from the auto-fix fallback attempting to edit pyproject.toml after the false-positive verify failure.

Evidence

Validation

  • python -m pytest tests/scripts/test_sync_test_dependencies_mapping.py
  • python -m py_compile scripts/sync_test_dependencies.py templates/consumer-repo/scripts/sync_test_dependencies.py
  • scripts/sync_templates.sh
  • scripts/validate_template_completeness.py

@github-actions

github-actions Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@stranske
stranske temporarily deployed to agent-standard May 4, 2026 20:42 — with GitHub Actions Inactive
@stranske
stranske marked this pull request as ready for review May 4, 2026 20:43
Copilot AI review requested due to automatic review settings May 4, 2026 20:43
@agents-workflows-bot

agents-workflows-bot Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

Automated Status Summary

Head SHA: 865bac3
Latest Runs: ⏳ pending — Gate
Required contexts: Gate / gate, Health 45 Agents Guard / guard
Required: core tests (3.12): ⏳ pending, core tests (3.13): ⏳ pending, docker smoke: ⏳ pending, gate: ⏳ pending

Workflow / Job Result Logs
(no jobs reported) ⏳ pending

Coverage Overview

  • Coverage history entries: 1

Coverage Trend

Metric Value
Current 93.12%
Baseline 85.00%
Delta +8.12%
Minimum 70.00%
Status ✅ Pass

Top Coverage Hotspots (lowest coverage)

File Coverage Missing
src/cli_parser.py 81.8% 4
src/percentile_calculator.py 95.0% 1
src/aggregator.py 95.0% 2
src/__init__.py 100.0% 0
src/ndjson_parser.py 100.0% 0

Updated automatically; will refresh on subsequent CI/Docker completions.


Keepalive checklist

Scope

No scope information available

Tasks

  • No tasks defined

Acceptance criteria

  • No acceptance criteria defined

@stranske
stranske temporarily deployed to agent-standard May 4, 2026 20:45 — with GitHub Actions Inactive
@github-actions

github-actions Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes false-positive Python CI failures caused by scripts/sync_test_dependencies.py --verify incorrectly treating some standard-library imports as undeclared third-party dependencies, and adds a missing module-to-package mapping for jwtPyJWT. It keeps the repository script and the consumer-template copy aligned and adds regression tests covering the imports observed in recent Wave 1 sync PR logs.

Changes:

  • Expand stdlib detection by adding missing stdlib modules and augmenting STDLIB_MODULES with sys.stdlib_module_names when available.
  • Add MODULE_TO_PACKAGE["jwt"] = "PyJWT" to correctly satisfy imports of jwt when PyJWT is declared.
  • Add regression tests to ensure both the repo script and consumer template behave identically for these mappings/stdlib cases.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
scripts/sync_test_dependencies.py Improves stdlib-module classification and adds jwtPyJWT mapping to prevent false missing-dependency reports.
templates/consumer-repo/scripts/sync_test_dependencies.py Mirrors the same stdlib and mapping fixes in the consumer template copy.
tests/scripts/test_sync_test_dependencies_mapping.py Adds regression coverage verifying jwt mapping and stdlib-module inclusion for both script locations.

stranske added a commit that referenced this pull request May 5, 2026
…TECTION_TOKEN in health-44

Wave 1's state-fingerprint helper (#1998 + #2002 wireup) broke
Health 44 enforce because the workflow's GITHUB_TOKEN can't access
the actions/variables endpoint even with `actions: write` set —
that endpoint requires a token with Variables permission (PAT,
GitHub App, or fine-grained PAT).

Resulting failure observed on every PR running Health 44 enforce
since #2002 merged (incl. PR #2006, PR #2007 today):

  GET /repos/stranske/Workflows/actions/variables/STATE_FINGERPRINT_HEALTH_44_GATE_BRANCH_PROTECTION_*
  failed: 403 "Resource not accessible by integration"

Two-part fix:

1) `scripts/state_fingerprint.py` — `RepoVariableStorage` now treats
   401/403 from the variables API as "storage unavailable" rather
   than fatal. Read returns None (no prior fingerprint), write skips
   silently, and a warning goes to stderr so the operator sees the
   misconfiguration in workflow logs. The existing 404 (no prior)
   path is unchanged.

   Effect: any workflow that adopts `--storage repo-variable` but
   doesn't have the right token degrades gracefully (skips the
   optimization, runs anyway) instead of failing outright. Future
   Wave 1+ workflows using repo-variable storage benefit from this.

2) `.github/workflows/health-44-gate-branch-protection.yml` — uses
   `BRANCH_PROTECTION_TOKEN` (already used downstream by `enforce`)
   when present, falling back to `GITHUB_TOKEN`. Now the
   fingerprint optimization actually works when the secret is
   configured.

Existing 6 tests in tests/scripts/test_state_fingerprint.py still
pass. py_compile clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
stranske added a commit that referenced this pull request May 5, 2026
…back (#2010)

* fix(keepalive): handle no-checklist draft PRs with accurate disposition

Phase 6 sync-PR review surfaced two related bugs in
keepalive_orchestrator_gate_runner.js (Copilot review on stranske/*
sync PRs):

- routeDraftToHuman() emitted "0 unchecked checklist item(s)" when
  the PR had no checkboxes at all, suggesting the user just needed
  to check boxes that didn't exist.
- The branching at line 404 fell through to the same "needs human"
  path for both genuine missing-acceptance-items cases and PRs that
  legitimately have no checklist at all.

This change distinguishes the no-checklist case end-to-end:

- Adds a noChecklist flag in the caller (computed once where
  checkboxCounts is built).
- Threads noChecklist through routeDraftToHuman so the comment body
  and summary line accurately describe "no acceptance checklist
  found" vs "N unchecked items".
- Adds a distinct reason key 'pr-draft-no-checklist' so weekly
  metrics can distinguish the two cases.

Lockstep edit: canonical .github/scripts/ + templates/consumer-repo/
both updated identically. node --check passes on both.

Out of scope here: the perceived "missing closing brace" Copilot
flagged was already addressed by PR #1985 / #1986 on 2026-04-30 —
the GraphQL mutation block in markDraftReadyForReview() has the
correct three closing braces. The isConcreteAgentLabel() concern
about agent:rate-limited / agent:retry routing as concrete agent
labels is separate and needs broader review of the keepalive
loop's label-routing semantics; deferred.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(state-fingerprint): graceful fallback on 401/403 + use BRANCH_PROTECTION_TOKEN in health-44

Wave 1's state-fingerprint helper (#1998 + #2002 wireup) broke
Health 44 enforce because the workflow's GITHUB_TOKEN can't access
the actions/variables endpoint even with `actions: write` set —
that endpoint requires a token with Variables permission (PAT,
GitHub App, or fine-grained PAT).

Resulting failure observed on every PR running Health 44 enforce
since #2002 merged (incl. PR #2006, PR #2007 today):

  GET /repos/stranske/Workflows/actions/variables/STATE_FINGERPRINT_HEALTH_44_GATE_BRANCH_PROTECTION_*
  failed: 403 "Resource not accessible by integration"

Two-part fix:

1) `scripts/state_fingerprint.py` — `RepoVariableStorage` now treats
   401/403 from the variables API as "storage unavailable" rather
   than fatal. Read returns None (no prior fingerprint), write skips
   silently, and a warning goes to stderr so the operator sees the
   misconfiguration in workflow logs. The existing 404 (no prior)
   path is unchanged.

   Effect: any workflow that adopts `--storage repo-variable` but
   doesn't have the right token degrades gracefully (skips the
   optimization, runs anyway) instead of failing outright. Future
   Wave 1+ workflows using repo-variable storage benefit from this.

2) `.github/workflows/health-44-gate-branch-protection.yml` — uses
   `BRANCH_PROTECTION_TOKEN` (already used downstream by `enforce`)
   when present, falling back to `GITHUB_TOKEN`. Now the
   fingerprint optimization actually works when the secret is
   configured.

Existing 6 tests in tests/scripts/test_state_fingerprint.py still
pass. py_compile clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: apply Black formatting to state_fingerprint.py 401/403 fallback

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@stranske
stranske temporarily deployed to agent-standard May 5, 2026 03:08 — with GitHub Actions Inactive
@stranske
stranske merged commit 988e5fe into main May 5, 2026
34 checks passed
@stranske
stranske deleted the fix/sync-pr-python-ci-pinning branch May 5, 2026 03:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants