Skip to content

Relock pytest that dependabot downgraded, drop tox from the dev group - #776

Open
RonnyPfannschmidt wants to merge 2 commits into
pytest-dev:mainfrom
RonnyPfannschmidt:fix/uv-lock-pytest-downgrade
Open

RonnyPfannschmidt wants to merge 2 commits into
pytest-dev:mainfrom
RonnyPfannschmidt:fix/uv-lock-pytest-downgrade

Conversation

@RonnyPfannschmidt

Copy link
Copy Markdown
Member

Written by Claude Opus 5.5 via Claude Code for the pluggy maintainers; I prompted it, it did the work, I read it.

#756 (virtualenv bump) also downgraded pytest 9.0.3 → 3.2.5, pytest-benchmark 5.2.3 → 3.1.1 and tox 4.53 → 1.9.2 in uv.lock. pytest 3.2.5 imports imp, so uv run pytest no longer starts on Python 3.12+. CI is unaffected because tox installs its own dependencies.

Cause: dependabot relocks from files fetched through the API, without git, and pretends the project version via SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PLUGGY: [tool.setuptools_scm] fallback_version, else "0.0.0" (dependabot/dependabot-core#13945). As pluggy 0.0.0, no current pytest (pluggy>=1.5) or tox (pluggy>=1.6) can be installed, so the resolver silently picked releases that predate the dependency.

Changes:

  • fallback_version = "1.6.0+fallback". It is a workaround for dependabot, not a real version; the local label keeps it off PyPI.
  • A pytest>=8 floor, so a bogus version makes the relock fail instead of downgrading.
  • Relock pytest and pytest-benchmark.
  • Drop tox from the dev group. Nothing used that copy: CI installs its own, the downstream runner builds its own venvs, and releasing only needs a tox on PATH. Installed in the project environment, it runs on the editable pluggy under test.
  • The development docs now use uv, and uvx tox for the matrix; RELEASING.rst uses uvx tox -e release. The old pip install -e .[dev] named an extra that doesn't exist.

Checked:

  • A simulated dependabot relock (no git, fallback version, --upgrade-package virtualenv) keeps pytest 9.1.1.
  • With 0.0.0 the relock fails as unsatisfiable.
  • A git-less build gets 1.6.0+fallback.
  • uvx tox -e docs passes.

RonnyPfannschmidt and others added 2 commits October 11, 2026 10:33
Dependabot's uv updater relocks without git and pretends the project
version through SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PLUGGY, using the
setuptools-scm fallback_version or "0.0.0" when there is none. As pluggy
0.0.0, no current pytest (pluggy>=1.5,<2) or tox (pluggy>=1.6) is
installable, so 6f8fa68 silently resolved pytest 3.2.5, pytest-benchmark
3.1.1 and tox 1.9.2. pytest 3.2.5 imports `imp` and cannot start on
Python 3.12+, so `uv run pytest` fails on main.

Set fallback_version to 1.6.0+fallback, which satisfies both consumers;
the local label marks it as fake and PyPI refuses local versions. Floor
pytest>=8 and tox>=4 so a future bogus version fails the relock instead
of downgrading. Relock pytest, pytest-benchmark and tox.

Co-Authored-By: Claude Opus 5.5 via Claude Code <noreply@anthropic.com>
Nothing uses the tox installed into the project environment: CI installs
its own, the downstream runner builds its own venvs, and releasing only
needs a tox on PATH. Installed there it runs on the editable pluggy under
test, and its pluggy>=1.6 requirement was the second dependency that a
bogus dependabot version downgraded.

Document uv as the development setup, with tox run as a tool via uvx;
the old `pip install -e .[dev]` named an extra that does not exist.
Reword the fallback_version comment to say it only serves dependabot.

Co-Authored-By: Claude Opus 5.5 via Claude Code <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant