Skip to content

BUILD-12353 Route mise Python tools through Repox - #338

Closed
SamirM-BE wants to merge 6 commits into
masterfrom
feat/smarini/BUILD-12353-pipIndexUrl
Closed

SamirM-BE wants to merge 6 commits into
masterfrom
feat/smarini/BUILD-12353-pipIndexUrl

Conversation

@SamirM-BE

@SamirM-BE SamirM-BE commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Keep the company-wide config-pip and config-uv actions unchanged.
  • Configure the three affected test workflows locally for both mise's metadata lookup and whichever installer backend it selects (uv tool or pipx).
  • Update this repo's pre-commit pin to disable virtualenv's direct periodic seed metadata checks.

Test plan

  • pre-commit run on changed files
  • focused ShellSpec coverage for the local mise index helper
  • GitHub checks pass
  • Harden Runner shows Repox traffic and no pypi.org or files.pythonhosted.org in the affected jobs

@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

BUILD-12353

Comment thread config-pip/action.yml Outdated
Comment thread config-pip/action.yml Outdated
@SamirM-BE
SamirM-BE marked this pull request as ready for review August 24, 2026 08:45
@SamirM-BE
SamirM-BE requested a review from a team as a code owner August 24, 2026 08:45
Copilot AI lite review requested due to automatic review settings August 24, 2026 08:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the local config-pip composite action to export pip index-related environment variables so that tools which ignore ~/.pip/pip.conf (e.g., pipx, mise pip backends, setup-python) can still use Repox instead of public PyPI, and updates CI workflows to run config-pip before mise-based installs.

Changes:

  • Export PIP_INDEX_URL, VIRTUALENV_INDEX_URL, and PIP_TRUSTED_HOST from the config-pip action (derived from ~/.pip/pip.conf).
  • Run ./config-pip earlier in multiple test workflows so mise/pipx installations inherit the Repox configuration.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
config-pip/action.yml Adds a step to export pip index env vars for tools that don’t read pip.conf.
.github/workflows/test-update-release-channel.yml Ensures config-pip runs before mise so check-jsonschema install uses Repox.
.github/workflows/test-shell-scripts.yml Ensures config-pip runs before mise/pipx tool installation.
.github/workflows/test-build-number.yml Runs config-pip before mise in the relevant test job.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread config-pip/action.yml Outdated
Comment on lines +100 to +105
index_url="$(awk -F ' = ' '/^index-url/ {print $2}' "${HOME}/.pip/pip.conf")"
rest="${index_url#https://}"
rest="${rest#http://}"
rest="${rest##*@}"
host="${rest%%/*}"
echo "::add-mask::${index_url}"
@SamirM-BE
SamirM-BE marked this pull request as draft August 24, 2026 09:01
@SamirM-BE SamirM-BE changed the title BUILD-12353 Export PIP_INDEX_URL from config-pip BUILD-12353 Configure uv default index for mise Python tools Aug 24, 2026
@SamirM-BE SamirM-BE changed the title BUILD-12353 Configure uv default index for mise Python tools BUILD-12353 Route mise Python tools through Repox Aug 24, 2026
@gitar-bot

gitar-bot Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Code Review ✅ Approved 2 resolved / 2 findings

Routes mise Python tools through Repox by adding a configuration script and associated ShellSpec tests, addressing the unsafe TLS verification and config parsing crash findings.

✅ 2 resolved
✅ Security: PIP_TRUSTED_HOST disables TLS verification for Repox host

📄 config-pip/action.yml:111-112
Setting PIP_TRUSTED_HOST tells pip to treat the Repox host as trusted even without valid HTTPS, which suppresses certificate verification for all subsequent steps and weakens protection against MITM. The generated pip.conf (config.sh) does not set trusted-host and Repox is served over valid HTTPS, so this variable is unnecessary. Consider dropping the PIP_TRUSTED_HOST export unless a specific tool genuinely requires it.

✅ Edge Case: Export step crashes if pip.conf lacks [global] index-url

📄 config-pip/action.yml:100-101
c["global"]["index-url"] raises KeyError (non-zero exit) if the section/key is ever missing or the file is empty, failing the action after config.sh already succeeded. It is currently guaranteed to exist, but for robustness use c.get("global", "index-url", fallback="") and skip the exports when empty, mirroring the existing host guard.

Implementation Status ✅ 1 of 1 objectives covered
✅ BUILD-12353 - 1 of 1 objectives covered

This PR routes mise Python tools through Repox by configuring PIP_INDEX_URL, UV_DEFAULT_INDEX, and MISE_PIPX_REGISTRY_URL locally in the affected workflows via a bash script and associated tests.

✅ 1 covered here
  • ✅ Route mise Python tools through Repox by configuring PIP_INDEX_URL, UV_DEFAULT_INDEX, and MISE_PIPX_REGISTRY_URL locally in affected workflows
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqubecloud

Copy link
Copy Markdown

@SamirM-BE
SamirM-BE marked this pull request as ready for review August 24, 2026 09:20

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not adding this to config-pip?

@matemoln

Copy link
Copy Markdown
Contributor

Superseded by the central config-pip change in the new PR — env export belongs in config-pip/config.sh rather than a repo-local .github/scripts/configure-mise-python-index.sh. Please close this PR once the central fix merges.

@SamirM-BE

Copy link
Copy Markdown
Contributor Author

Closing as requested.

@SamirM-BE SamirM-BE closed this Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants