Skip to content

fix(ci): sync uv.lock and let release-please update it on every release - #94

Merged
HC-ONLINE merged 1 commit into
mainfrom
fix/release-please-uv-lock
Oct 1, 2026
Merged

HC-ONLINE merged 1 commit into
mainfrom
fix/release-please-uv-lock

Conversation

@HC-ONLINE

Copy link
Copy Markdown
Owner

Problem

The Docker build on main failed after merging PR #93 (release-please):

error: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided.

release-please bumped pyproject.toml to 2.23.0 but uv.lock still recorded the project version 2.22.0, so uv sync --locked in the Dockerfile rejected the stale lockfile. This will happen on every release.

Changes

  • uv.lock: regenerate project version entry (2.22.0 -> 2.23.0) — fixes the current failed build.
  • .github/release-please-config.json (new): release-please manifest config with an extra-files TOML updater (JSONPath into uv.lock) so every release PR also updates the project version inside uv.lock.
  • .github/release-please-manifest.json (new): version seed ".": "2.23.0" (matches the current v2.23.0 tag).
  • .github/workflows/release-please.yml: migrate from simple mode (release-type: python) to manifest mode (config-file/manifest-file) — extra-files is only supported in manifest mode.
  • .github/workflows/ci.yml: add uv lock --check guard so lockfile drift fails CI in seconds, before the Docker build.

Validation

  • JSONPath verified against uv.lock with jsonpath-plus (the library release-please uses): exactly 1 match (/package/8/version).
  • End-to-end with GenericToml from the release-please package: updates exactly 1 line, format preserved.
  • Simulated the next release (pyproject 2.24.0 + updater output) -> uv lock --check passes.
  • Dockerfile command uv sync --locked --no-install-project --extra api passes locally.
  • pre-commit run --files ... (check-yaml, check-toml, prettier, whitespace) passes.

The combined JSONPath filter (@.name == 'ciberwebscan' || @.name.value == 'ciberwebscan') handles both the tagged and untagged TOML representations used by release-please's parser.

@HC-ONLINE
HC-ONLINE merged commit 23e664c into main Oct 1, 2026
5 of 6 checks passed
@HC-ONLINE
HC-ONLINE deleted the fix/release-please-uv-lock branch October 1, 2026 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant