-
Notifications
You must be signed in to change notification settings - Fork 1.4k
uv: Support parsing and updating tool.uv.required-version field #14581
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
a02e697
f0aeb47
163d352
6598611
2076a00
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,7 +16,7 @@ module Uv | |
| class FileFetcher < Dependabot::Python::SharedFileFetcher | ||
| extend T::Sig | ||
|
|
||
| ECOSYSTEM_SPECIFIC_FILES = T.let(%w(uv.lock).freeze, T::Array[String]) | ||
| ECOSYSTEM_SPECIFIC_FILES = T.let(%w(uv.lock uv.toml).freeze, T::Array[String]) | ||
|
|
||
| REQUIREMENT_FILE_PATTERNS = T.let( | ||
| { | ||
|
|
@@ -34,13 +34,12 @@ class FileFetcher < Dependabot::Python::SharedFileFetcher | |
|
|
||
| sig { override.returns(T::Array[String]) } | ||
| def self.ecosystem_specific_required_files | ||
| # uv.lock is not a standalone required file - it requires pyproject.toml | ||
| [] | ||
| %w(uv.toml) | ||
| end | ||
|
|
||
| sig { override.returns(String) } | ||
| def self.required_files_message | ||
| "Repo must contain a requirements.txt, uv.lock, requirements.in, or pyproject.toml" | ||
| "Repo must contain a requirements.txt, uv.lock, uv.toml, requirements.in, or pyproject.toml" | ||
| end | ||
|
Comment on lines
35
to
43
|
||
|
|
||
| private | ||
|
|
@@ -51,6 +50,7 @@ def ecosystem_specific_files | |
| files += readme_files | ||
| files += license_files | ||
| files += uv_lock_files | ||
| files += uv_toml_files | ||
| files += workspace_member_files | ||
| files += version_source_files | ||
| files | ||
|
|
@@ -261,6 +261,12 @@ def child_uv_lock_files | |
| child_requirement_files.select { |f| f.name.end_with?("uv.lock") } | ||
| end | ||
|
|
||
| sig { returns(T::Array[Dependabot::DependencyFile]) } | ||
| def uv_toml_files | ||
| file = fetch_file_if_present("uv.toml") | ||
| file ? [file] : [] | ||
| end | ||
|
|
||
| sig { override.returns(T::Array[Dependabot::DependencyFile]) } | ||
| def req_txt_and_in_files | ||
| return @req_txt_and_in_files if @req_txt_and_in_files | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,114 @@ | ||
| # typed: strict | ||
| # frozen_string_literal: true | ||
|
|
||
| require "toml-rb" | ||
| require "dependabot/dependency" | ||
| require "dependabot/file_parsers/base/dependency_set" | ||
| require "dependabot/uv/file_parser" | ||
| require "dependabot/uv/requirement" | ||
|
|
||
| module Dependabot | ||
| module Uv | ||
| class FileParser | ||
| # Parses the `required-version` field from `uv.toml` and | ||
| # `[tool.uv]` in `pyproject.toml` to track the pinned uv tool version. | ||
| class UvVersionParser | ||
| extend T::Sig | ||
|
|
||
| UV_TOOL_DEP_NAME = "uv:required-version" | ||
|
|
||
| sig { params(dependency_files: T::Array[Dependabot::DependencyFile]).void } | ||
| def initialize(dependency_files:) | ||
| @dependency_files = dependency_files | ||
| end | ||
|
|
||
| sig { returns(Dependabot::FileParsers::Base::DependencySet) } | ||
| def dependency_set | ||
| deps = Dependabot::FileParsers::Base::DependencySet.new | ||
|
|
||
| uv_toml_dep = parse_from_uv_toml | ||
| deps << uv_toml_dep if uv_toml_dep | ||
|
|
||
| pyproject_dep = parse_from_pyproject | ||
| deps << pyproject_dep if pyproject_dep | ||
|
|
||
| deps | ||
| end | ||
|
|
||
| private | ||
|
|
||
| sig { returns(T::Array[Dependabot::DependencyFile]) } | ||
| attr_reader :dependency_files | ||
|
|
||
| sig { returns(T.nilable(Dependabot::Dependency)) } | ||
| def parse_from_uv_toml | ||
| file = uv_toml_file | ||
| return unless file | ||
|
|
||
| parsed = TomlRB.parse(T.must(file.content)) | ||
| required_version = parsed["required-version"] | ||
| return unless required_version.is_a?(String) && !required_version.empty? | ||
|
|
||
| build_dependency(required_version, file.name) | ||
| rescue TomlRB::ParseError, TomlRB::ValueOverwriteError | ||
| nil | ||
| end | ||
|
|
||
| sig { returns(T.nilable(Dependabot::Dependency)) } | ||
| def parse_from_pyproject | ||
| return unless pyproject | ||
|
|
||
| parsed = TomlRB.parse(T.must(T.must(pyproject).content)) | ||
| required_version = parsed.dig("tool", "uv", "required-version") | ||
| return unless required_version.is_a?(String) && !required_version.empty? | ||
|
|
||
| build_dependency(required_version, T.must(pyproject).name) | ||
| rescue TomlRB::ParseError, TomlRB::ValueOverwriteError | ||
| nil | ||
| end | ||
|
|
||
| sig { params(requirement_string: String, filename: String).returns(Dependabot::Dependency) } | ||
| def build_dependency(requirement_string, filename) | ||
| Dependabot::Dependency.new( | ||
| name: UV_TOOL_DEP_NAME, | ||
| version: extract_exact_version(requirement_string), | ||
| requirements: [{ | ||
| requirement: requirement_string, | ||
| file: filename, | ||
| source: nil, | ||
| groups: ["uv-required-version"] | ||
| }], | ||
| package_manager: "uv" | ||
| ) | ||
| end | ||
|
|
||
| sig { params(requirement_string: String).returns(T.nilable(String)) } | ||
| def extract_exact_version(requirement_string) | ||
| reqs = Requirement.requirements_array(requirement_string) | ||
| return nil unless reqs.length == 1 | ||
|
|
||
| req = T.must(reqs.first) | ||
| return nil unless req.exact? | ||
|
|
||
| req.requirements.first&.last&.to_s | ||
| end | ||
|
|
||
| sig { returns(T.nilable(Dependabot::DependencyFile)) } | ||
| def uv_toml_file | ||
| @uv_toml_file ||= T.let( | ||
| dependency_files.find { |f| f.name == "uv.toml" }, | ||
| T.nilable(Dependabot::DependencyFile) | ||
| ) | ||
| end | ||
|
|
||
| sig { returns(T.nilable(Dependabot::DependencyFile)) } | ||
| def pyproject | ||
| @pyproject ||= T.let( | ||
| dependency_files.find { |f| f.name == "pyproject.toml" }, | ||
| T.nilable(Dependabot::DependencyFile) | ||
| ) | ||
| end | ||
| end | ||
| end | ||
| end | ||
| end |
Uh oh!
There was an error while loading. Please reload this page.