Install the focused guard test runner from wheels only - #136
Conversation
Reviewer's GuideThe focused guard workflow now installs pytest 8.3.4 with pip restricted to wheels, preventing source-package build scripts while leaving guard behavior, command bytes, and the canonical verification suite unchanged; accompanying spec artifacts document the correction and validation. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The unquoted :all: argument makes the workflow invalid YAML, preventing CI from running.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Hardens the focused guard CI job by requiring wheel-only pytest installation.
Changes:
- Adds
--only-binary=:all:to the pinned pytest install. - Documents the security correction and verification plan.
| File | Description |
|---|---|
.github/workflows/tests.yml |
Enforces wheel-only installation. |
specs/003-binary-only-guard-runner/spec.md |
Defines the requirement. |
specs/003-binary-only-guard-runner/plan.md |
Records the implementation plan. |
specs/003-binary-only-guard-runner/tasks.md |
Records completion and verification. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |




Summary
Follow up on openRepoTools#135's late Sonar annotation: install the focused
guard test runner using
--only-binary=:all:so pip cannot execute sourcepackage build scripts. Preserve the pinned pytest version and canonical wrapper.
Runtime guard behavior and vendored command bytes are unchanged.
Implementation:
specs/003-binary-only-guard-runner/.CI reruns the focused guard and hygiene checks and Sonar analysis.
This session is outside a lane under brettheap/new-workstation#47.
Summary by Sourcery
Install the focused guard test runner from wheels only while preserving its pinned version and existing runtime behavior.
Bug Fixes:
CI:
Chores: