fix(ci): removed the PSR GitPython compat shim - #80
Conversation
Prepared ahead of time -- see the merge precondition below. The shim added in 0ef07ef re-attaches Actor.name_email_regex, which GitPython 3.1.60 removed while fixing GHSA-g5vv-9gxw-82hx (ReDoS, high). python-semantic-release 10.6.1 reads that attribute on every config load, so without the shim the release step aborts before inspecting a single commit. python-semantic-release#1477 drops that read. Once a release carrying it exists, the shim is dead weight and re-attaching a regex that upstream deliberately deleted stops being defensible. * Shim block and its self-test removed from the install step * PYTHONPATH prefix removed from the semantic-release invocation * Install floor raised to `python-semantic-release>10.6.1` Why the floor rather than a bare install: it turns a premature merge into an immediate, legible failure. Verified against PyPI today -- pip reports "No matching distribution found for python-semantic-release>10.6.1" and the job stops at the install step, instead of resolving 10.6.1 and dying later with the cryptic "type object 'Actor' has no attribute 'name_email_regex'". The floor is a minimum, not a pin, so GitPython and PSR both stay on their current releases. MERGE PRECONDITION: a python-semantic-release release newer than 10.6.1 must exist AND must no longer reference name_email_regex. Latest release as of 2026-08-26 is 10.6.1 (2026-07-06); #1477 is merged on main but unreleased. Refs: python-semantic-release/python-semantic-release#1477
🤖 AI SummaryType: pull_request This pull_request requires review. Please check the full description for details. This summary was automatically generated by AI to help with triage and may not be 100% accurate. |
Precondition check — the upstream blocker has clearedRe-ran the verification commands from the description. python-semantic-release 10.6.2 was released on 2026-08-28, two days after this PR was opened.
Verification performed: So the What is still openOnly the end-to-end proof — a fresh dispatch of a consumer pipeline. As the description notes, gh workflow run python-automatic-release.yml --repo bauer-group/XPD-AIModelSync --ref mainI have deliberately not triggered that — it runs against another repository, and confirming a release pipeline is green is your call rather than something to fire off during triage. Rebase note
Leaving this as a draft. Once you have a green dispatch, it is a mark-ready-and-merge. |
Conflict around the semantic-release invocation: main added the tag-before/ tag-after detection that decides `released`, this branch removed the shim's PYTHONPATH prefix from the same line. Both kept - main's detection block verbatim, calling a bare `semantic-release --verbose version`. Merge precondition met in the meantime: python-semantic-release 10.6.2 (2026-08-28) is one commit ahead of the #1477 merge and zero behind, so the release that drops the Actor.name_email_regex read exists. Verified with a pip dry-run: the floor resolves to 10.6.2, and >10.6.2 still fails loudly at the install step as designed.
Merge precondition erfüllt — Draft aufgehoben
Beide prüfbaren Bedingungen mit Die Fail-Loud-Eigenschaft des Floors, wegen der er statt eines nackten Konflikt aufgelöst
Keine Reste des Shims mehr in der Datei — Der dritte Haken ist nach dem Merge nicht mehr separat zu besorgen: der nächste Push auf |
🔍 PR Validation ReportOverall Status: ✅ PASSED Validation Results
🎉 Great job! All validation checks passed. This PR is ready for review. Automated validation by Automation Templates |
|
🎉 This PR is included in version 10.1.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Korrektur zur dritten Precondition — und die eigentliche VerifikationIn meinem Kommentar oben stand, der dritte Haken erledige sich nach dem Merge von selbst, weil „der nächste Push auf Die grünen Pipeline-Läufe auf Stattdessen lokal gegen die echten Pakete geprüftvenv, Installation über genau den Floor aus diesem PR, kein Shim auf dem Und die Kontrolle, die das eigentlich beweist: Ein Nebenbefund, der den Blast Radius weiter verkleinertGitPython hat Das Attribut fehlte also nur im Fenster 3.1.60. Die ursprüngliche Bruchkombination existiert damit von beiden Seiten nicht mehr — PSR liest es nicht mehr, und GitPython hätte es bis 4.0 ohnehin wieder. Der Merge war entsprechend risikoarm. Wer den geänderten Pfad trotzdem im CI sehen will, braucht einen Dispatch-Run in einem Consumer-Repo, das |
Prepared in advance so the cleanup is a review-and-merge, not a re-investigation.
Background
GitPython 3.1.60 removed
Actor.name_email_regexwhile fixing GHSA-g5vv-9gxw-82hx (ReDoS in commit author/committer parsing, high). python-semantic-release 10.6.1 still reads that attribute on every config load, so the release step died before inspecting a single commit.0ef07ef works around this with a
sitecustomize.pyshim that re-attaches the regex, loaded viaPYTHONPATHscoped to thesemantic-releasecall. That is the right call today — it keeps GitPython current instead of pinning back to the vulnerable 3.1.59, and the re-attached regex only ever sees the configured (trusted)commit_author, never repository data.python-semantic-release#1477 drops the read. Once a release carrying it exists, the shim is dead weight — and re-attaching a regex upstream deliberately deleted for a security fix stops being defensible.
What this changes
PYTHONPATHprefix removed from thesemantic-releaseinvocation"python-semantic-release>10.6.1"Net: -42 / +2. The install step returns to its pre-incident shape, plus the floor.
Why the floor instead of a bare install
It turns a premature merge into an immediate, legible failure. Verified against PyPI on 2026-08-26:
The job stops at the install step with an obvious message, rather than resolving 10.6.1 and dying later with
type object 'Actor' has no attribute 'name_email_regex'.It is a minimum, not a pin — GitPython and PSR both stay on their current releases, consistent with the org rule against pinning by default.
Merge precondition
name_email_regex(i.e. contains #1477)Status on 2026-08-26: latest release is 10.6.1 (2026-07-06). #1477 is merged on
mainbut unreleased.Verification commands
Note that
gh run rerunwill not exercise a change to this file — a re-run replays the reusable-workflow version resolved when the original run started. Use a fresh dispatch or push.Conflict risk
This branch touches
.github/workflows/python-semantic-release.yml, which PRs #68 and #71 may also touch. If either lands first, rebase this branch before merging.