Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates the local config-pip composite action to export pip index-related environment variables so that tools which ignore ~/.pip/pip.conf (e.g., pipx, mise pip backends, setup-python) can still use Repox instead of public PyPI, and updates CI workflows to run config-pip before mise-based installs.
Changes:
- Export
PIP_INDEX_URL,VIRTUALENV_INDEX_URL, andPIP_TRUSTED_HOSTfrom theconfig-pipaction (derived from~/.pip/pip.conf). - Run
./config-pipearlier in multiple test workflows so mise/pipx installations inherit the Repox configuration.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| config-pip/action.yml | Adds a step to export pip index env vars for tools that don’t read pip.conf. |
| .github/workflows/test-update-release-channel.yml | Ensures config-pip runs before mise so check-jsonschema install uses Repox. |
| .github/workflows/test-shell-scripts.yml | Ensures config-pip runs before mise/pipx tool installation. |
| .github/workflows/test-build-number.yml | Runs config-pip before mise in the relevant test job. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| index_url="$(awk -F ' = ' '/^index-url/ {print $2}' "${HOME}/.pip/pip.conf")" | ||
| rest="${index_url#https://}" | ||
| rest="${rest#http://}" | ||
| rest="${rest##*@}" | ||
| host="${rest%%/*}" | ||
| echo "::add-mask::${index_url}" |
Code Review ✅ Approved 2 resolved / 2 findingsRoutes mise Python tools through Repox by adding a configuration script and associated ShellSpec tests, addressing the unsafe TLS verification and config parsing crash findings. ✅ 2 resolved✅ Security: PIP_TRUSTED_HOST disables TLS verification for Repox host
✅ Edge Case: Export step crashes if pip.conf lacks [global] index-url
Implementation Status ✅ 1 of 1 objectives covered✅ BUILD-12353 - 1 of 1 objectives coveredThis PR routes mise Python tools through Repox by configuring PIP_INDEX_URL, UV_DEFAULT_INDEX, and MISE_PIPX_REGISTRY_URL locally in the affected workflows via a bash script and associated tests. ✅ 1 covered here
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|
julien-carsique-sonarsource
left a comment
There was a problem hiding this comment.
Why not adding this to config-pip?
|
Superseded by the central |
|
Closing as requested. |



Summary
config-pipandconfig-uvactions unchanged.uv toolorpipx).Test plan
pre-commit runon changed filespypi.orgorfiles.pythonhosted.orgin the affected jobs