CI has never passed: the dependency audit fails on Postulo itself #75
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#75
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Found while auditing
main. CI has never passed. Every one of the 38 runs since theproject moved into the
postuloorganisation is red, and the README carries a CI badge.What is wrong
Two separate faults.
1. The dependency audit fails on Postulo itself
uv syncinstalls Postulo as an editable package.pip-audit --strictfails onanything it cannot look up, and Postulo is not on PyPI:
--skip-editabledoes not help;--strictstill counts a skip as a failure.The consequence is worse than a red badge. The README promises that "dependencies are
checked for known vulnerabilities on every run and on a schedule, so a fresh disclosure is
noticed without anyone having to remember to look". The audit stopped at the project and
never reported on the dependencies at all, and a real disclosure would have arrived as one
more red run among thirty-eight. (Checked by hand while auditing: Python and npm are both
clean right now. The promise was unkept, not violated.)
2. Nothing on a release branch is checked
Work moved onto per-release branches when 0.2.0 closed.
0.3.0has commits on it andzero CI runs — the filter said
mainand the commits were going somewhere else.The fix
Audit the lock file rather than the installed environment:
--no-emit-projectleaves Postulo out by construction, so--strictis kept: adependency that becomes unauditable still fails the build, which is the entire point of
it. This audits exactly what will be installed rather than an environment that also
contains the project. Verified locally: 80 pinned packages audited, exit 0.
And run on the release branches, not only
main.Not included
The plugin repositories are red too — 7 of the 10 repositories in the organisation,
everything except the two browser extensions and
postulo-templates, which has no CI atall. Their cause is different:
postulo-helloworld's complete CI sequence — sync, ruff,catalogue compile, pytest — passes locally, so the failure is environmental, most likely
the runner fetching
git+https://source.tiagoagueda.com/postulo/postulo.gitfrom insideits container. That needs the job logs and is its own issue.
Classification
Bug. The build has been reporting failure regardless of the state of the code, which is the
same as reporting nothing.
Reopening in spirit rather than in state: the audit fix landed as
2a80712and was correct, but it was not the only reason CI failed. Run 725 was still red afterwards. The rest is #76.