Conversation
pip.conf alone is ignored by pipx, mise, and uv; export PIP_INDEX_URL, UV_DEFAULT_INDEX, MISE_PIPX_REGISTRY_URL, and PIP_CONFIG_FILE after writing pip.conf and mask authenticated URLs in logs.
|
There was a problem hiding this comment.
Pull request overview
Updates the config-pip composite action so it not only writes ~/.pip/pip.conf for Repox, but also persists Repox index environment variables (for pip/uv/mise/pipx) and masks authenticated index URLs in GitHub Actions logs.
Changes:
- Extend
config-pip/config.shto emit::add-mask::entries for authenticated index URLs and appendPIP_INDEX_URL,UV_DEFAULT_INDEX,MISE_PIPX_REGISTRY_URL, andPIP_CONFIG_FILEto$GITHUB_ENV. - Expand ShellSpec coverage to assert the new masking output and the environment variables written to
$GITHUB_ENV. - Document the new exported environment variables and recommended step ordering in
README.md.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
config-pip/config.sh |
Adds masking and exports Repox index-related env vars via $GITHUB_ENV after generating pip.conf. |
spec/config-pip_spec.sh |
Updates expectations for the extra log lines and validates the new env vars are written. |
README.md |
Documents new env vars and notes that config-pip should run before tools that consume them. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| authenticated_index="https://${ARTIFACTORY_USERNAME}:${ARTIFACTORY_ACCESS_TOKEN}@${repox_host}/api/pypi/sonarsource-pypi/simple" | ||
| registry_url="${authenticated_index}/{}/" |
There was a problem hiding this comment.
⚠️ Bug: MISE_PIPX_REGISTRY_URL simple-index breaks wheel-only pipx tools
MISE_PIPX_REGISTRY_URL is set to …/api/pypi/sonarsource-pypi/simple/{}/. In every released mise version (checked v2026.5.9, v2026.6.14, v2026.8.1 — the versions this repo pins in config-uv/action.yml:103 and .github/workflows/test-shell-scripts.yml:25), a registry_url that does not contain /json is fetched as HTML and versions are extracted with the regex href=["'][^"']*/([^/]+)\.tar\.gz… (src/backend/pipx.rs:144-160 and :209-220). Only sdist links are recognised, so for any wheel-only package (no .tar.gz on the index) mise gets an empty version list and mise install pipx:<pkg> / @latest resolution fails, where previously the pypi.org JSON API returned all versions. Wheel support for the simple index exists only on mise main (versions_from_simple_index handling .whl), not in a release. Either wait for/require a mise version with wheel support, or document the limitation and the requirement to pin sdist-publishing packages in the README note added at README.md:1218.
Document the wheel-only limitation next to the new ordering note so consumers are not surprised by "no versions found" failures.:
# README.md (config-pip section)
> **Note:** `MISE_PIPX_REGISTRY_URL` points at the Repox PEP 503 simple index. Released mise
> versions only discover versions from sdist (`.tar.gz`) links on a simple index, so
> `pipx:` tools that publish wheels only cannot be resolved via `@latest`; pin such tools to
> an exact version or install them with `uv tool` / `pipx` directly (they use `PIP_INDEX_URL`).
Was this helpful? React with 👍 / 👎
| { | ||
| echo "PIP_INDEX_URL=${authenticated_index}" | ||
| echo "UV_DEFAULT_INDEX=${authenticated_index}" | ||
| echo "MISE_PIPX_REGISTRY_URL=${registry_url}" | ||
| echo "PIP_CONFIG_FILE=${pip_conf_file}" | ||
| } >> "$GITHUB_ENV" |
There was a problem hiding this comment.
💡 Quality: Repo's own mise workflows still resolve pipx tools from pypi.org
The PR's test plan is to observe "Repox traffic and no pypi.org / files.pythonhosted.org" on this repo's mise workflows, but the only workflow that runs ./config-pip is pre-commit.yml:13; test-shell-scripts.yml (and test-build-number.yml, test-update-release-channel.yml) invoke jdx/mise-action — which installs pipx and pipx:check-jsonschema — without ever running config-pip, so no PIP_INDEX_URL / MISE_PIPX_REGISTRY_URL is present and those installs still hit pypi.org. Add a ./config-pip step before the jdx/mise-action step in those workflows (or state in the PR that consumer wiring is out of scope) so the stated verification is actually possible.
Run config-pip before mise-action in test-shell-scripts.yml (and the other mise-based test workflows) so pipx/mise resolve from Repox.:
- uses: ./config-npm
- uses: ./config-pip
- uses: jdx/mise-action@e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d # v4.2.0
with:
version: 2026.6.14
Was this helpful? React with 👍 / 👎
CI failed: Pre-commit check failed due to a markdownlint line-length violation in README.md.Overview1 failure found in total logs analyzed, related to a style/formatting check during pre-commit execution. FailuresMarkdownlint Line Length Violation (confidence: high)
Summary
Code Review
|
| Auto-apply | Compact | Unblock |
|
|
|
Was this helpful? React with 👍 / 👎 | Gitar
|
superseeded by https://github.com/SonarSource/mise-action-wrapper |



Summary
config-pip/config.shto exportPIP_INDEX_URL,UV_DEFAULT_INDEX,MISE_PIPX_REGISTRY_URL, andPIP_CONFIG_FILEafter writingpip.conf.::add-mask::.Supersedes #338 — the central fix belongs in
config-pip/rather than a repo-local.github/scripts/configure-mise-python-index.sh.Test plan
shellspec spec/config-pip_spec.shpypi.org/files.pythonhosted.org