Repository navigation
chore: sync the e2b floor of the Python Code Interpreter and Desktop SDKs on version - #1926
Conversation
…SDKs on version Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
There was a problem hiding this comment.
TASTE.md review: complies — 0 violations. The PR only changes the postVersion release scripts in packages/code-interpreter-python/package.json and packages/desktop-python/package.json (no public SDK API surface); checked against T-43 (shell-string escaping), T-54/T-56 (package structure / no hardcoded SDK version), and the API-shape, parity, error, and docs rules, none of which this tooling-only change touches.
Package ArtifactsBuilt from 975cbc3. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-2.52.1-devin-1790862253-sync-python-e2b-floor.0.tgzCLI ( npm install ./e2b-cli-2.21.1-devin-1790862253-sync-python-e2b-floor.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.1-devin-1790862253-sync-python-e2b-floor.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1790862253-sync-python-e2b-floor.0.tgzPython SDK ( pip install ./e2b-2.52.0+devin.1790862253.sync.python.e2b.floor-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.1+devin.1790862253.sync.python.e2b.floor-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.0+devin.1790862253.sync.python.e2b.floor-py3-none-any.whl |
|
check review |
Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
There was a problem hiding this comment.
Looks good, straightforward config change. Both edits are identical and mechanical: appending a uv add --frozen "e2b>=<python-sdk version>,<3.0.0" call to the existing postVersion script in the two Python-SDK-dependent packages, keeping the published dependency floor in sync with the sibling python-sdk version.
What was reviewed: the two package.json diffs line-by-line (confirmed only the postVersion script changed, identical pattern applied to both files); the version-read mechanism (reads python-sdk's package.json, not pyproject.toml, avoiding a race with python-sdk's own postVersion); the hardcoded <3.0.0 ceiling and its interaction with a pending desktop-python patch changeset — both are edge cases outside this diff's scope, not introduced bugs.
Extended reasoning...
The diff touches only the postVersion npm script in two package.json files (code-interpreter-python, desktop-python), adding a uv add --frozen call to sync the e2b dependency floor with python-sdk's version; no security-sensitive surface (auth, crypto, permissions) is touched. The change is small, symmetric across both affected packages (matching repo convention of keeping parallel Python packages in sync), and the bug hunt reported zero findings. The three ruled-out candidate issues (hardcoded <3.0.0 ceiling, interaction with a pending patch changeset, and network-call fragility in postVersion) are edge cases that don't represent correctness bugs in this diff and were adequately reasoned through by the PR author's own testing description.
This review covers commit b2416d0, which is no longer the latest commit on this pull request; later commits are not covered by it.
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…#1926), unblocking the release (#1951) ## Summary Fixes the failed release run [Publish / Build and test SDK](https://github.com/e2b-dev/E2B/actions/runs/37520925792/job/112468741075) on `main` (1de92fc). Reverts #1926. ``` packages/desktop-python postVersion: e2b-desktop 2.6.1 => 2.6.1 ... packages/desktop-python postPublish: error: Local file and index file do not match for e2b_desktop-2.6.1-py3-none-any.whl. Local: sha256=6b05209c…, Remote: sha256=cf1cfd6d… ERR_PNPM_RECURSIVE_RUN_FIRST_FAIL @e2b/desktop-python@2.6.1 postPublish: `uv build && uv publish --trusted-publishing always --check-url https://pypi.org/simple/` ``` **Root cause:** #1926 made `postVersion` rewrite `e2b>=<sdk version>` in `pyproject.toml` on **every** release, even when the package itself is not released. This release only bumped python-sdk, so Desktop's floor went from `e2b>=2.44.0` to `e2b>=2.53.0` while its version stayed at `2.6.1`. `pnpm run -r postPublish` rebuilds every Python package, and `uv publish --check-url` only skips files that are byte-identical to what's already on PyPI. The rebuilt `e2b_desktop-2.6.1` had different METADATA, so uv rejected it, and the whole publish aborted. Nothing was uploaded: PyPI still has `e2b` 2.52.1 and `e2b-code-interpreter` 2.10.1, and `changeset publish` (npm) never ran. **Changes:** - `postVersion` in `code-interpreter-python` / `desktop-python` goes back to `uv version --frozen <own version>` (a revert of #1926). - Restores `e2b>=2.44.0,<3.0.0` in `packages/desktop-python/pyproject.toml`. The release commit 2438c92 had written `e2b>=2.53.0` there, and 2.6.1 on PyPI declares `>=2.44.0`. Without this, the next release would fail the same way. - `code-interpreter-python` keeps the `e2b>=2.53.0` that 2438c92 wrote. It came with that package's own version bump (2.10.2, not yet published), so there's no mismatch. ## Verification - `uv build` (uv 0.10.0, the CI version) of `desktop-python` with the restored floor gives the same sha256 as both files on PyPI (wheel `cf1cfd6d…`, sdist `dc715a77…`). So `--check-url` will skip them again. ## Follow-up - The 2.53.0 / 2.10.2 versions are committed on `main` but were never published to npm or PyPI. The next release with a changeset bumps the versions past them (the workflow keeps failed versions on purpose). - After this revert, Desktop's `e2b` floor has to be bumped by hand again. Link to Devin session: https://app.devin.ai/sessions/328bb32ba7344529858415273d98c0ec Open in Devin Desktop: https://app.devin.ai/desktop/session/328bb32ba7344529858415273d98c0ec?variant=devin <!-- devin-review-badge-begin --> --- <a href="https://app.devin.ai/review/e2b-dev/e2b/pull/1951" target="_blank"><picture><source media="(prefers-color-scheme: dark)" srcset="https://static.devin.ai/assets/gh-devin-review-dark.svg?v=4"><img src="https://static.devin.ai/assets/gh-devin-review-light.svg?v=4" alt="Devin Review"></picture></a> <!-- devin-review-badge-end --> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Summary
The Python Code Interpreter and Desktop SDKs already resolve
e2bfrom the workspace ([tool.uv.sources] e2b = { workspace = true }). That only affects local dev and CI:uv builddropstool.uv.sourcesand publishes thee2b>=X,<3.0.0range from[project].dependenciesexactly as written. So the floor had to be bumped by hand and drifted: Desktop still says>=2.44.0while CI only ever tests it against the current SDK (2.52.0).This change makes
postVersion(run bypnpm run versionafterchangeset version) also set the range toe2b>=<sdk version>,<<sdk major + 1>.0.0. That mirrors what pnpm'sworkspace:^does for the JS SDKs:"postVersion": "uv version --frozen <own version> + && uv add --frozen \"$(node -p \"const v = require('../python-sdk/package.json').version; 'e2b>=' + v + ',<' + (Number(v.split('.')[0]) + 1) + '.0.0'\")\""package.json, notpyproject.toml: changesets writespackage.jsonbefore anypostVersionruns, while python-sdk's ownpostVersion(which updatespyproject.toml) may run at the same time underpnpm run -r.e2b>=3.0.0,<4.0.0instead of an impossible range.--frozenleaves[tool.uv.sources]untouched; the existingpnpm run -r lockstep refreshesuv.lockafterwards.I ran
pnpm run postVersionon a copy of both packages. Desktop's floor went2.44.0 → 2.52.0, Code Interpreter's stayed the same (already 2.52.0), anduv lock --checkpassed for both. With the SDK version set to 3.0.0, the expression givese2b>=3.0.0,<4.0.0.Link to Devin session: https://app.devin.ai/sessions/cc34bb02be3a42679a5eab9529034b76
Open in Devin Desktop: https://app.devin.ai/desktop/session/cc34bb02be3a42679a5eab9529034b76?variant=devin
Requested by: @mishushakov