Skip to content

BUILD-12410 Export Repox index env vars from config-pip - #339

Closed
matemoln wants to merge 1 commit into
masterfrom
feat/mmolnar/config-pip-env-vars
Closed

matemoln wants to merge 1 commit into
masterfrom
feat/mmolnar/config-pip-env-vars

Conversation

@matemoln

Copy link
Copy Markdown
Contributor

Summary

  • Extend config-pip/config.sh to export PIP_INDEX_URL, UV_DEFAULT_INDEX, MISE_PIPX_REGISTRY_URL, and PIP_CONFIG_FILE after writing pip.conf.
  • Mask authenticated index URLs in workflow logs via ::add-mask::.
  • Document step ordering (config-pip before setup-python / mise / pipx / uv) and the new output environment variables.

Supersedes #338 — the central fix belongs in config-pip/ rather than a repo-local .github/scripts/configure-mise-python-index.sh.

Test plan

  • shellspec spec/config-pip_spec.sh
  • Harden-Runner on ci-github-actions mise test workflows shows Repox traffic and no pypi.org / files.pythonhosted.org

pip.conf alone is ignored by pipx, mise, and uv; export PIP_INDEX_URL,
UV_DEFAULT_INDEX, MISE_PIPX_REGISTRY_URL, and PIP_CONFIG_FILE after writing
pip.conf and mask authenticated URLs in logs.
@matemoln
matemoln requested a review from a team as a code owner August 27, 2026 16:24
Copilot AI lite review requested due to automatic review settings August 27, 2026 16:24
@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Export Repox index env vars from config-pip BUILD-12410 Export Repox index env vars from config-pip Aug 27, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

BUILD-12410

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the config-pip composite action so it not only writes ~/.pip/pip.conf for Repox, but also persists Repox index environment variables (for pip/uv/mise/pipx) and masks authenticated index URLs in GitHub Actions logs.

Changes:

  • Extend config-pip/config.sh to emit ::add-mask:: entries for authenticated index URLs and append PIP_INDEX_URL, UV_DEFAULT_INDEX, MISE_PIPX_REGISTRY_URL, and PIP_CONFIG_FILE to $GITHUB_ENV.
  • Expand ShellSpec coverage to assert the new masking output and the environment variables written to $GITHUB_ENV.
  • Document the new exported environment variables and recommended step ordering in README.md.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
config-pip/config.sh Adds masking and exports Repox index-related env vars via $GITHUB_ENV after generating pip.conf.
spec/config-pip_spec.sh Updates expectations for the extra log lines and validates the new env vars are written.
README.md Documents new env vars and notes that config-pip should run before tools that consume them.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread config-pip/config.sh
Comment on lines +26 to +27
authenticated_index="https://${ARTIFACTORY_USERNAME}:${ARTIFACTORY_ACCESS_TOKEN}@${repox_host}/api/pypi/sonarsource-pypi/simple"
registry_url="${authenticated_index}/{}/"

@gitar-bot gitar-bot Bot Aug 27, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Bug: MISE_PIPX_REGISTRY_URL simple-index breaks wheel-only pipx tools

MISE_PIPX_REGISTRY_URL is set to …/api/pypi/sonarsource-pypi/simple/{}/. In every released mise version (checked v2026.5.9, v2026.6.14, v2026.8.1 — the versions this repo pins in config-uv/action.yml:103 and .github/workflows/test-shell-scripts.yml:25), a registry_url that does not contain /json is fetched as HTML and versions are extracted with the regex href=["'][^"']*/([^/]+)\.tar\.gz… (src/backend/pipx.rs:144-160 and :209-220). Only sdist links are recognised, so for any wheel-only package (no .tar.gz on the index) mise gets an empty version list and mise install pipx:<pkg> / @latest resolution fails, where previously the pypi.org JSON API returned all versions. Wheel support for the simple index exists only on mise main (versions_from_simple_index handling .whl), not in a release. Either wait for/require a mise version with wheel support, or document the limitation and the requirement to pin sdist-publishing packages in the README note added at README.md:1218.

Document the wheel-only limitation next to the new ordering note so consumers are not surprised by "no versions found" failures.:

# README.md (config-pip section)
> **Note:** `MISE_PIPX_REGISTRY_URL` points at the Repox PEP 503 simple index. Released mise
> versions only discover versions from sdist (`.tar.gz`) links on a simple index, so
> `pipx:` tools that publish wheels only cannot be resolved via `@latest`; pin such tools to
> an exact version or install them with `uv tool` / `pipx` directly (they use `PIP_INDEX_URL`).

Was this helpful? React with 👍 / 👎

Comment thread config-pip/config.sh
Comment on lines +38 to +43
{
echo "PIP_INDEX_URL=${authenticated_index}"
echo "UV_DEFAULT_INDEX=${authenticated_index}"
echo "MISE_PIPX_REGISTRY_URL=${registry_url}"
echo "PIP_CONFIG_FILE=${pip_conf_file}"
} >> "$GITHUB_ENV"

@gitar-bot gitar-bot Bot Aug 27, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: Repo's own mise workflows still resolve pipx tools from pypi.org

The PR's test plan is to observe "Repox traffic and no pypi.org / files.pythonhosted.org" on this repo's mise workflows, but the only workflow that runs ./config-pip is pre-commit.yml:13; test-shell-scripts.yml (and test-build-number.yml, test-update-release-channel.yml) invoke jdx/mise-action — which installs pipx and pipx:check-jsonschema — without ever running config-pip, so no PIP_INDEX_URL / MISE_PIPX_REGISTRY_URL is present and those installs still hit pypi.org. Add a ./config-pip step before the jdx/mise-action step in those workflows (or state in the PR that consumer wiring is out of scope) so the stated verification is actually possible.

Run config-pip before mise-action in test-shell-scripts.yml (and the other mise-based test workflows) so pipx/mise resolve from Repox.:

- uses: ./config-npm
- uses: ./config-pip
- uses: jdx/mise-action@e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d # v4.2.0
  with:
    version: 2026.6.14

Was this helpful? React with 👍 / 👎

@gitar-bot

gitar-bot Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
CI failed: Pre-commit check failed due to a markdownlint line-length violation in README.md.

Overview

1 failure found in total logs analyzed, related to a style/formatting check during pre-commit execution.

Failures

Markdownlint Line Length Violation (confidence: high)

  • Type: tooling
  • Affected jobs: 98590630647
  • Related to change: yes
  • Root cause: README.md line 1218 exceeds the maximum line length of 140 characters (actual: 237).
  • Suggested fix: Wrap or shorten the long line at line 1218 in README.md to conform to the 140-character limit.

Summary

  • Change-related failures: 1 pre-commit markdownlint check failure.
  • Infrastructure/flaky failures: 0 failures.
  • Recommended action: Update README.md to fix the line length violation and push the changes.
Code Review ⚠️ Changes requested 0 resolved / 2 findings

Exports Repox index environment variables from config-pip for pipx, mise, and uv, but changes are requested due to two open issues: MISE_PIPX_REGISTRY_URL simple-index breaks wheel-only pipx tools and the repo's own mise workflows still resolve pipx tools from pypi.org.

⚠️ Bug: MISE_PIPX_REGISTRY_URL simple-index breaks wheel-only pipx tools

📄 config-pip/config.sh:26-27 📄 config-pip/config.sh:41 🔗 mise pipx backend, released version

MISE_PIPX_REGISTRY_URL is set to …/api/pypi/sonarsource-pypi/simple/{}/. In every released mise version (checked v2026.5.9, v2026.6.14, v2026.8.1 — the versions this repo pins in config-uv/action.yml:103 and .github/workflows/test-shell-scripts.yml:25), a registry_url that does not contain /json is fetched as HTML and versions are extracted with the regex href=["'][^"']*/([^/]+)\.tar\.gz… (src/backend/pipx.rs:144-160 and :209-220). Only sdist links are recognised, so for any wheel-only package (no .tar.gz on the index) mise gets an empty version list and mise install pipx:<pkg> / @latest resolution fails, where previously the pypi.org JSON API returned all versions. Wheel support for the simple index exists only on mise main (versions_from_simple_index handling .whl), not in a release. Either wait for/require a mise version with wheel support, or document the limitation and the requirement to pin sdist-publishing packages in the README note added at README.md:1218.

Document the wheel-only limitation next to the new ordering note so consumers are not surprised by "no versions found" failures.
# README.md (config-pip section)
> **Note:** `MISE_PIPX_REGISTRY_URL` points at the Repox PEP 503 simple index. Released mise
> versions only discover versions from sdist (`.tar.gz`) links on a simple index, so
> `pipx:` tools that publish wheels only cannot be resolved via `@latest`; pin such tools to
> an exact version or install them with `uv tool` / `pipx` directly (they use `PIP_INDEX_URL`).
💡 Quality: Repo's own mise workflows still resolve pipx tools from pypi.org

📄 config-pip/config.sh:38-43

The PR's test plan is to observe "Repox traffic and no pypi.org / files.pythonhosted.org" on this repo's mise workflows, but the only workflow that runs ./config-pip is pre-commit.yml:13; test-shell-scripts.yml (and test-build-number.yml, test-update-release-channel.yml) invoke jdx/mise-action — which installs pipx and pipx:check-jsonschema — without ever running config-pip, so no PIP_INDEX_URL / MISE_PIPX_REGISTRY_URL is present and those installs still hit pypi.org. Add a ./config-pip step before the jdx/mise-action step in those workflows (or state in the PR that consumer wiring is out of scope) so the stated verification is actually possible.

Run config-pip before mise-action in test-shell-scripts.yml (and the other mise-based test workflows) so pipx/mise resolve from Repox.
- uses: ./config-npm
- uses: ./config-pip
- uses: jdx/mise-action@e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d # v4.2.0
  with:
    version: 2026.6.14
🤖 Prompt for agents
Code Review: Exports Repox index environment variables from `config-pip` for `pipx`, `mise`, and `uv`, but changes are requested due to two open issues: `MISE_PIPX_REGISTRY_URL` simple-index breaks wheel-only pipx tools and the repo's own mise workflows still resolve pipx tools from pypi.org.

1. ⚠️ Bug: MISE_PIPX_REGISTRY_URL simple-index breaks wheel-only pipx tools
   Files: config-pip/config.sh:26-27, config-pip/config.sh:41

   `MISE_PIPX_REGISTRY_URL` is set to `…/api/pypi/sonarsource-pypi/simple/{}/`. In every released mise version (checked v2026.5.9, v2026.6.14, v2026.8.1 — the versions this repo pins in `config-uv/action.yml:103` and `.github/workflows/test-shell-scripts.yml:25`), a `registry_url` that does not contain `/json` is fetched as HTML and versions are extracted with the regex `href=["'][^"']*/([^/]+)\.tar\.gz…` (src/backend/pipx.rs:144-160 and :209-220). Only sdist links are recognised, so for any wheel-only package (no `.tar.gz` on the index) `mise` gets an empty version list and `mise install pipx:<pkg>` / `@latest` resolution fails, where previously the pypi.org JSON API returned all versions. Wheel support for the simple index exists only on mise `main` (`versions_from_simple_index` handling `.whl`), not in a release. Either wait for/require a mise version with wheel support, or document the limitation and the requirement to pin sdist-publishing packages in the README note added at README.md:1218.

   Fix (Document the wheel-only limitation next to the new ordering note so consumers are not surprised by "no versions found" failures.):
   # README.md (config-pip section)
   > **Note:** `MISE_PIPX_REGISTRY_URL` points at the Repox PEP 503 simple index. Released mise
   > versions only discover versions from sdist (`.tar.gz`) links on a simple index, so
   > `pipx:` tools that publish wheels only cannot be resolved via `@latest`; pin such tools to
   > an exact version or install them with `uv tool` / `pipx` directly (they use `PIP_INDEX_URL`).

2. 💡 Quality: Repo's own mise workflows still resolve pipx tools from pypi.org
   Files: config-pip/config.sh:38-43

   The PR's test plan is to observe "Repox traffic and no pypi.org / files.pythonhosted.org" on this repo's mise workflows, but the only workflow that runs `./config-pip` is `pre-commit.yml:13`; `test-shell-scripts.yml` (and `test-build-number.yml`, `test-update-release-channel.yml`) invoke `jdx/mise-action` — which installs `pipx` and `pipx:check-jsonschema` — without ever running `config-pip`, so no `PIP_INDEX_URL` / `MISE_PIPX_REGISTRY_URL` is present and those installs still hit pypi.org. Add a `./config-pip` step before the `jdx/mise-action` step in those workflows (or state in the PR that consumer wiring is out of scope) so the stated verification is actually possible.

   Fix (Run config-pip before mise-action in test-shell-scripts.yml (and the other mise-based test workflows) so pipx/mise resolve from Repox.):
   - uses: ./config-npm
   - uses: ./config-pip
   - uses: jdx/mise-action@e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d # v4.2.0
     with:
       version: 2026.6.14

Tip

Comment Gitar fix CI or enable auto-apply: gitar auto-apply:on

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.
Unblock → Override a blocking verdict and allow merging.

Comment with these commands to change the behavior for this request:

Auto-apply Compact Unblock
gitar auto-apply:on         
gitar display:verbose         
gitar unblock         

Was this helpful? React with 👍 / 👎 | Gitar

@matemoln
matemoln marked this pull request as draft August 27, 2026 16:33
@matemoln

Copy link
Copy Markdown
Contributor Author

@matemoln matemoln closed this Aug 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants