-
-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Expand file tree
/
Copy pathpyproject.toml
More file actions
205 lines (184 loc) · 6.82 KB
/
Copy pathpyproject.toml
File metadata and controls
205 lines (184 loc) · 6.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
[build-system]
requires = ["setuptools>=61.0", "wheel"]
build-backend = "setuptools.build_meta"
[project]
name = "pr-agent"
version = "0.47.0"
authors = [
{ name = "QodoAI", email = "ofir.f@qodo.ai" },
]
maintainers = [
{ name = "Naor Peled", email = "me@naor.dev" },
{ name = "Ofir Friedman", email = "ofir.f@qodo.ai" },
]
description = "PR-Agent aims to help efficiently review and handle pull requests, by providing AI feedback and suggestions."
readme = "README.md"
requires-python = ">=3.12"
keywords = ["AI", "Agents", "Pull Request", "Automation", "Code Review"]
license = { file = "LICENSE" }
classifiers = [
"Intended Audience :: Developers",
"Programming Language :: Python :: 3",
]
# Exact versions for this repo's own builds (Docker, CI, uv sync) come from
# uv.lock. Security-sensitive packages below declare >=patched,<next-major
# ranges instead of == pins so pip consumers can pull security patches on
# their own cadence (#2523); the floor is the last vetted patched release.
dependencies = [
"aiohttp>=3.14.3,<4",
"anthropic>=0.69.0",
"certifi>=2026.7.22",
"dynaconf>=3.3.5,<4",
"fastapi>=0.141.1,<1",
"GitPython>=3.1.62,<4",
"starlette>=1.6.0,<2",
"Jinja2==3.1.6",
"litellm==1.104.0",
"loguru==0.7.3",
"openai>=1.55.3",
"PyJWT>=2.15.1,<3",
"PyYAML==6.0.3",
"retry==0.9.2",
"starlette-context==0.3.6",
"tiktoken==0.14.0",
"ujson>=5.13.0,<6",
"unidiff==0.7.5",
# Declare urllib3 directly because gerrit_provider.py imports urllib3.util; the >=2.8.0
# floor is a security requirement and follows the >=patched,<next-major convention above.
"urllib3>=2.8.0,<3",
"uvicorn>=0.31.1,<1",
"tenacity==8.2.3",
"langfuse==3.14.5",
"gunicorn==23.0.0",
"pydantic==2.13.3",
# LiteLLM declares pydantic-settings as a base dependency and imports it unconditionally from
# litellm/integrations/otel/model/config.py. Keep the exact pin to lock the resolved transitive version.
# Recheck LiteLLM's declared constraint on upgrade; the observability guard covers callback imports.
"pydantic-settings==2.14.2",
"html2text==2024.2.26",
# pr_agent/telemetry imports these directly; already resolved transitively via
# langfuse and litellm, pinned here to lock the version the code is tested against.
"opentelemetry-api==1.43.0",
"opentelemetry-sdk==1.43.0",
"opentelemetry-exporter-otlp-proto-http==1.43.0",
# Prometheus scrape endpoint for [otel] command telemetry (native /metrics on
# the webhook apps). Multiprocess-capable; see pr_agent/telemetry/prometheus.py.
"prometheus-client==0.21.1",
]
[project.urls]
"Homepage" = "https://github.com/the-pr-agent/pr-agent"
"Documentation" = "https://docs.pr-agent.ai/"
"Repository" = "https://github.com/the-pr-agent/pr-agent"
"Issues" = "https://github.com/the-pr-agent/pr-agent/issues"
[tool.setuptools]
include-package-data = true
[tool.setuptools.package-data]
pr_agent = ["py.typed"]
[tool.setuptools.packages.find]
where = ["."]
include = [
"pr_agent*",
] # include pr_agent and any sub-packages it finds under it.
[project.optional-dependencies]
# Git/provider integrations are optional so a plain package install does not pull every SDK.
github = ["PyGithub>=2.10,<3"]
gitlab = ["python-gitlab==8.3.0"]
bitbucket = ["atlassian-python-api==3.41.4"]
azure = [
"azure-devops==7.1.0b4",
"azure-identity==1.25.0",
"msrest==0.7.1",
]
codecommit = ["boto3==1.43.78"]
gitea = ["giteapy==1.0.8"]
google = [
"google-cloud-aiplatform==1.154.0",
# google-cloud-aiplatform==1.154.0 requires storage <4,>=1.32.0 on py<3.13 and <4,>=3.10.0 on py>=3.13.
# Pin per-Python so existing installs are unchanged and py3.13 resolves. See #2480.
"google-cloud-storage==2.10.0; python_version < '3.13'",
"google-cloud-storage==3.12.0; python_version >= '3.13'",
# Keep protobuf explicit to lock the transitive version resolved with the gRPC dependency stack.
# Revalidate compatibility when updating grpcio-status or related Google/gRPC dependencies.
"protobuf==6.33.6",
]
mosaico = ["a2a-sdk[http-server]==1.0.3"]
# Preserve the dependency set that the published Docker images shipped before provider SDKs became optional.
all = ["pr-agent[github,gitlab,bitbucket,azure,codecommit,gitea,google,mosaico]"]
# AWS Lambda deployment (docker/Dockerfile.lambda).
# Keep mangum >=0.21.0 for Python 3.14: older releases call
# asyncio.get_event_loop() with no fallback, which raises RuntimeError
# when no loop is set. Skip 0.20.0, whose 3.14 support was reverted
# upstream; 0.22.0 is end-to-end tested against a real Lambda runtime.
lambda = ["mangum==0.22.0"]
# OTLP/gRPC transport for pr-agent telemetry (OTEL.OTLP_PROTOCOL = "grpc").
# The default OTLP/HTTP transport needs no extra: its exporter is a base dependency.
otel-grpc = ["opentelemetry-exporter-otlp-proto-grpc==1.43.0"]
# LangChainOpenAIHandler. Install with: uv sync --extra langchain
langchain = [
"langchain",
"langchain-core",
"langchain-openai",
]
[project.scripts]
pr-agent = "pr_agent.cli:run"
[dependency-groups]
# Keep the full optional integration matrix available to the unit suite without publishing it as a base dependency.
integration-dev = ["pr-agent[all]"]
# 'similar issue' tool. Install with: uv sync --group similar-issue.
# Keep this a dependency group rather than a published extra so the vector
# database drivers stay out of the base install.
similar-issue = [
"pandas", # imported directly by the qdrant indexing path
"pinecone==10.0.0",
"lancedb==0.38.0",
"qdrant-client==1.15.1",
]
dev = [
{ include-group = "integration-dev" },
"pytest==9.1.1",
"pytest-asyncio>=1.4.0",
"pytest-cov==7.1.0",
"httpx==0.28.1",
"pre-commit>=4,<5",
"ruff==0.16.10",
]
[tool.uv]
# Floor, not "==": Dependabot's uv 0.12.18 failed the exact pin with tool_version_not_supported.
required-version = ">=0.12.10"
[tool.ruff]
line-length = 120
lint.select = [
"E", # pycodestyle
"F", # Pyflakes
"B", # flake8-bugbear
"I", # isort
]
lint.fixable = [
"I001", # import sorting
"F401", # unused imports
"F541", # f-string without placeholders
]
lint.unfixable = [
"B", # Avoid trying to fix flake8-bugbear (`B`) violations.
]
lint.exclude = ["api/code_completions"]
# Everything below is a pre-existing
# violation deferred so ruff runs green on adoption — fix the code and drop
# the entry. TODO: burn this list down.
lint.ignore = [
"E722", # bare `except`
"B023", # function definition uses loop variable
"B904", # raise without `from` inside `except`
]
[tool.ruff.lint.per-file-ignores]
# Ignore import-position and unused-import in __init__.py (re-export modules).
"__init__.py" = ["E402", "F401"]
"pr_agent/servers/help.py" = ["E501"] # very long urls
[tool.pytest.ini_options]
asyncio_mode = "auto"
testpaths = ["tests/unittest"]
python_files = ["test_*.py"]
python_classes = ["Test*"]
python_functions = ["test_*"]
addopts = "--color=yes --import-mode=importlib"
console_output_style = "progress"