fix: audit locked Python dependencies reproducibly#22
Merged
Conversation
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
furkanerday
approved these changes
Jul 24, 2026
furkanerday
left a comment
Collaborator
There was a problem hiding this comment.
Reviewed the complete diff, PR description, all conversation and review history, unresolved threads, repository policies, relevant contracts and tests, required checks, and commit sign-offs at 068114a. All required checks pass, no actionable thread remains, and I found no blocking issue.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pip-auditRoot Cause
The previous audit inspected the synchronized environment. That environment includes the local, unreleased project version. During a release PR,
pip-auditcan treat that version as a published dependency and fail resolution before auditing third-party packages.The new path derives its input directly from
uv.lock. It excludes the local project and audits the hash-checked third-party dependency set.Impact
Runtime APIs, package metadata, generated code, and public contracts do not change. Release PR #21 can return to metadata-only scope after this PR merges.
Validation
bash -n scripts/auditgit diff --checkSigned-off-by: kriptoburak kriptoburak@users.noreply.github.com
Note
Audit locked Python dependencies using exported requirements file with hashes
Replaces the previous approach of syncing a locked environment and inspecting site-packages with a flow that exports locked third-party dependencies to a temporary
requirements.txtand runspip-auditagainst it.uv exportwith--locked,--all-extras,--group pydantic-v2,--no-emit-project, and--format requirements-txtto generate the audit targetpip-auditwith--disable-pip,--require-hashes, and--requirementto audit the exported fileMacroscope summarized 2194737.