Skip to content

fix(ci): removed the PSR GitPython compat shim - #80

Merged
karlspace merged 2 commits into
mainfrom
fix/remove-psr-gitpython-compat-shim
Sep 2, 2026
Merged

karlspace merged 2 commits into
mainfrom
fix/remove-psr-gitpython-compat-shim

Conversation

@karlspace

Copy link
Copy Markdown
Contributor

⛔ Do not merge yet. Blocked on an upstream release — see Merge precondition.

Prepared in advance so the cleanup is a review-and-merge, not a re-investigation.

Background

GitPython 3.1.60 removed Actor.name_email_regex while fixing GHSA-g5vv-9gxw-82hx (ReDoS in commit author/committer parsing, high). python-semantic-release 10.6.1 still reads that attribute on every config load, so the release step died before inspecting a single commit.

0ef07ef works around this with a sitecustomize.py shim that re-attaches the regex, loaded via PYTHONPATH scoped to the semantic-release call. That is the right call today — it keeps GitPython current instead of pinning back to the vulnerable 3.1.59, and the re-attached regex only ever sees the configured (trusted) commit_author, never repository data.

python-semantic-release#1477 drops the read. Once a release carrying it exists, the shim is dead weight — and re-attaching a regex upstream deliberately deleted for a security fix stops being defensible.

What this changes

  • Shim block and its self-test removed from the install step
  • PYTHONPATH prefix removed from the semantic-release invocation
  • Install floor raised to "python-semantic-release>10.6.1"

Net: -42 / +2. The install step returns to its pre-incident shape, plus the floor.

Why the floor instead of a bare install

It turns a premature merge into an immediate, legible failure. Verified against PyPI on 2026-08-26:

ERROR: No matching distribution found for python-semantic-release>10.6.1

The job stops at the install step with an obvious message, rather than resolving 10.6.1 and dying later with type object 'Actor' has no attribute 'name_email_regex'.

It is a minimum, not a pin — GitPython and PSR both stay on their current releases, consistent with the org rule against pinning by default.

Merge precondition

  • A python-semantic-release release newer than 10.6.1 exists on PyPI
  • That release no longer references name_email_regex (i.e. contains #1477)
  • A dispatch run of a consumer repo's release pipeline is green

Status on 2026-08-26: latest release is 10.6.1 (2026-07-06). #1477 is merged on main but unreleased.

Verification commands

# 1. Has a newer release shipped?
curl -s https://pypi.org/pypi/python-semantic-release/json | jq -r .info.version

# 2. Is the offending read really gone from it?
pip download --no-deps --no-binary :all: "python-semantic-release>10.6.1" -d /tmp/psr
grep -r name_email_regex /tmp/psr   # expect: no matches

# 3. Prove it end-to-end before merging
gh workflow run python-automatic-release.yml --repo bauer-group/XPD-AIModelSync --ref main

Note that gh run rerun will not exercise a change to this file — a re-run replays the reusable-workflow version resolved when the original run started. Use a fresh dispatch or push.

Conflict risk

This branch touches .github/workflows/python-semantic-release.yml, which PRs #68 and #71 may also touch. If either lands first, rebase this branch before merging.

Prepared ahead of time -- see the merge precondition below.

The shim added in 0ef07ef re-attaches Actor.name_email_regex, which
GitPython 3.1.60 removed while fixing GHSA-g5vv-9gxw-82hx (ReDoS,
high). python-semantic-release 10.6.1 reads that attribute on every
config load, so without the shim the release step aborts before
inspecting a single commit.

python-semantic-release#1477 drops that read. Once a release carrying
it exists, the shim is dead weight and re-attaching a regex that
upstream deliberately deleted stops being defensible.

* Shim block and its self-test removed from the install step
* PYTHONPATH prefix removed from the semantic-release invocation
* Install floor raised to `python-semantic-release>10.6.1`

Why the floor rather than a bare install: it turns a premature merge
into an immediate, legible failure. Verified against PyPI today --
pip reports "No matching distribution found for
python-semantic-release>10.6.1" and the job stops at the install step,
instead of resolving 10.6.1 and dying later with the cryptic
"type object 'Actor' has no attribute 'name_email_regex'".

The floor is a minimum, not a pin, so GitPython and PSR both stay on
their current releases.

MERGE PRECONDITION: a python-semantic-release release newer than
10.6.1 must exist AND must no longer reference name_email_regex.
Latest release as of 2026-08-26 is 10.6.1 (2026-07-06); #1477 is
merged on main but unreleased.

Refs: python-semantic-release/python-semantic-release#1477
@karlspace karlspace added the ci label Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🤖 AI Summary

Type: pull_request
Title: fix(ci): removed the PSR GitPython compat shim
Author: @karlspace

This pull_request requires review. Please check the full description for details.


This summary was automatically generated by AI to help with triage and may not be 100% accurate.

@karlspace

Copy link
Copy Markdown
Contributor Author

Precondition check — the upstream blocker has cleared

Re-ran the verification commands from the description. python-semantic-release 10.6.2 was released on 2026-08-28, two days after this PR was opened.

Precondition Status
A PSR release newer than 10.6.1 exists on PyPI ✅ 10.6.2, uploaded 2026-08-28
That release no longer references name_email_regex ✅ verified — 0 occurrences
A dispatch run of a consumer release pipeline is green ⬜ still open — maintainer action

Verification performed:

$ curl -s https://pypi.org/pypi/python-semantic-release/json | jq -r .info.version
10.6.2

$ pip download --no-deps --no-binary :all: "python-semantic-release>10.6.1"
Successfully downloaded python-semantic-release   # -> python_semantic_release-10.6.2.tar.gz

$ # scanned every .py in the sdist
name_email_regex occurrences: 0

So the >10.6.1 floor now resolves rather than failing at install, and the attribute the shim re-attaches is genuinely no longer read. Both technical preconditions are met.

What is still open

Only the end-to-end proof — a fresh dispatch of a consumer pipeline. As the description notes, gh run rerun will not exercise this, since a re-run replays the reusable-workflow version resolved when the original run started. It needs a real dispatch or push:

gh workflow run python-automatic-release.yml --repo bauer-group/XPD-AIModelSync --ref main

I have deliberately not triggered that — it runs against another repository, and confirming a release pipeline is green is your call rather than something to fire off during triage.

Rebase note

.github/workflows/python-semantic-release.yml moved on main since this branch was cut: #84 bumped actions/setup-python v6 → v7 in it, and it also picked up the repository-wide version sweep. The changes sit on different lines from the shim removal, so no textual conflict is expected — but please rebase before merging so the branch carries the current file.

Leaving this as a draft. Once you have a green dispatch, it is a mark-ready-and-merge.

Conflict around the semantic-release invocation: main added the tag-before/
tag-after detection that decides `released`, this branch removed the shim's
PYTHONPATH prefix from the same line. Both kept - main's detection block
verbatim, calling a bare `semantic-release --verbose version`.

Merge precondition met in the meantime: python-semantic-release 10.6.2
(2026-08-28) is one commit ahead of the #1477 merge and zero behind, so the
release that drops the Actor.name_email_regex read exists. Verified with a
pip dry-run: the floor resolves to 10.6.2, and >10.6.2 still fails loudly at
the install step as designed.
@karlspace
karlspace marked this pull request as ready for review September 2, 2026 14:29
@karlspace

Copy link
Copy Markdown
Contributor Author

Merge precondition erfüllt — Draft aufgehoben

Precondition Status
PSR-Release neuer als 10.6.1 auf PyPI ✅ 10.6.2, veröffentlicht 2026-08-28T20:22Z
Enthält #1477 (kein name_email_regex-Read mehr) ✅ v10.6.2 ist 1 Commit ahead, 0 behind vom Merge-Commit 10afa8ec (gemergt 20:04Z, Release 18 Min später)
Grüner Release-Run ohne Shim ⬜ → wird direkt nach dem Merge vom eigenen Pipeline-Run erbracht

Beide prüfbaren Bedingungen mit pip gegengetestet:

python-semantic-release>10.6.1  → resolves to 10.6.2
python-semantic-release>10.6.2  → ERROR: No matching distribution found

Die Fail-Loud-Eigenschaft des Floors, wegen der er statt eines nackten pip install drinsteht, funktioniert also weiterhin.

Konflikt aufgelöst

main hat inzwischen die Tag-Erkennung ergänzt, die released bestimmt (TAGS_BEFORE / NEW_TAG) — genau an der Zeile, von der dieser Branch das PYTHONPATH-Präfix entfernt. Beides behalten: mains Block unverändert, mit einem blanken semantic-release --verbose version.

Keine Reste des Shims mehr in der Datei — psr-compat, sitecustomize, PSR_COMPAT und name_email_regex kommen nicht mehr vor. actionlint über alle 204 Workflows: 0 Findings.

Der dritte Haken ist nach dem Merge nicht mehr separat zu besorgen: der nächste Push auf main fährt diese Datei selbst, ohne Shim.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

🔍 PR Validation Report

Overall Status: ✅ PASSED

Validation Results

Check Status Details
Conventional Commits ⏭️ SKIP success
Security Scan ⏭️ SKIP Score: 100/100
License Compliance ⏭️ SKIP pass

🎉 Great job! All validation checks passed. This PR is ready for review.


Automated validation by Automation Templates

@karlspace
karlspace merged commit 810e6b2 into main Sep 2, 2026
28 checks passed
@karlspace
karlspace deleted the fix/remove-psr-gitpython-compat-shim branch September 2, 2026 14:37
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 10.1.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@karlspace

Copy link
Copy Markdown
Contributor Author

Korrektur zur dritten Precondition — und die eigentliche Verifikation

In meinem Kommentar oben stand, der dritte Haken erledige sich nach dem Merge von selbst, weil „der nächste Push auf main diese Datei selbst fährt". Das stimmt nicht. Dieses Repository releast sich mit Node-semantic-release; python-semantic-release.yml wird ausschließlich von zwei Beispielen referenziert:

github/workflows/examples/python-build/python-semantic-release.yml:33
github/workflows/examples/python-build/python-package.yml:83   (auskommentiert)

Die grünen Pipeline-Läufe auf 810e6b2 und 601dc79 haben den geänderten Pfad also nicht ausgeführt.

Stattdessen lokal gegen die echten Pakete geprüft

venv, Installation über genau den Floor aus diesem PR, kein Shim auf dem PYTHONPATH:

python-semantic-release 10.6.2
GitPython               3.1.61

$ semantic-release --noop version --print
1.0.0
exit=0

Und die Kontrolle, die das eigentlich beweist: name_email_regex kommt im installierten semantic_release-Paket an keiner Stelle mehr vor. #1477 ist im ausgelieferten Artefakt, nicht nur im Repo.

Ein Nebenbefund, der den Blast Radius weiter verkleinert

GitPython hat Actor.name_email_regex in 3.1.61 wieder eingeführt — als Deprecation mit Warnhinweis, Entfernung angekündigt für 4.0.0:

DeprecationWarning: Actor.name_email_regex is deprecated and will be removed in
GitPython 4.0.0 because searching long malformed strings with it can take
quadratic time.

Das Attribut fehlte also nur im Fenster 3.1.60. Die ursprüngliche Bruchkombination existiert damit von beiden Seiten nicht mehr — PSR liest es nicht mehr, und GitPython hätte es bis 4.0 ohnehin wieder.

Der Merge war entsprechend risikoarm. Wer den geänderten Pfad trotzdem im CI sehen will, braucht einen Dispatch-Run in einem Consumer-Repo, das python-semantic-release.yml@main aufruft — der bleibt der einzige echte End-to-End-Nachweis.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant