Skip to content

Install the focused guard test runner from wheels only - #136

Merged
brettheap merged 2 commits into
mainfrom
003-binary-only-guard-runner
Sep 30, 2026
Merged

brettheap merged 2 commits into
mainfrom
003-binary-only-guard-runner

Conversation

@brettheap

@brettheap brettheap commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Follow up on openRepoTools#135's late Sonar annotation: install the focused
guard test runner using --only-binary=:all: so pip cannot execute source
package build scripts. Preserve the pinned pytest version and canonical wrapper.

Runtime guard behavior and vendored command bytes are unchanged.
Implementation: specs/003-binary-only-guard-runner/.

CI reruns the focused guard and hygiene checks and Sonar analysis.
This session is outside a lane under brettheap/new-workstation#47.

Summary by Sourcery

Install the focused guard test runner from wheels only while preserving its pinned version and existing runtime behavior.

Bug Fixes:

  • Require the focused guard job to install its pinned pytest runner from binary distributions only, preventing source package build scripts from executing.

CI:

  • Document validation of the wheel-only runner installation through the focused guard and hygiene checks.

Chores:

  • Add implementation specification and task tracking for the binary-only guard runner change.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:47
@sourcery-ai

sourcery-ai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

The focused guard workflow now installs pytest 8.3.4 with pip restricted to wheels, preventing source-package build scripts while leaving guard behavior, command bytes, and the canonical verification suite unchanged; accompanying spec artifacts document the correction and validation.

File-Level Changes

Change Details Files
Require the focused CI job to install its pinned pytest runner exclusively from binary distributions.
  • Add pip's --only-binary=:all: option while preserving the existing pytest version and other install settings.
  • Document the follow-up specification, implementation plan, completed task, and verification scope.
.github/workflows/tests.yml
specs/003-binary-only-guard-runner/plan.md
specs/003-binary-only-guard-runner/spec.md
specs/003-binary-only-guard-runner/tasks.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

sourcery-ai[bot]
sourcery-ai Bot previously approved these changes Sep 30, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@brettheap

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The unquoted :all: argument makes the workflow invalid YAML, preventing CI from running.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Hardens the focused guard CI job by requiring wheel-only pytest installation.

Changes:

  • Adds --only-binary=:all: to the pinned pytest install.
  • Documents the security correction and verification plan.
File Description
.github/​workflows/​tests.yml Enforces wheel-only installation.
specs/​003-binary-only-guard-runner/​spec.md Defines the requirement.
specs/​003-binary-only-guard-runner/​plan.md Records the implementation plan.
specs/​003-binary-only-guard-runner/​tasks.md Records completion and verification.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/tests.yml Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:51
@sonarqubecloud

Copy link
Copy Markdown

@brettheap

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused security hardening is correct, scoped as described, and preserves the pinned runner and canonical test wrapper.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@brettheap
brettheap merged commit cbb5981 into main Sep 30, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants