Skip to content

fix(ci): install defusedxml lock in trusted uv quality gate - #2496

Open
seonghobae wants to merge 1 commit into
mainfrom
fix/trusted-uv-quality-defusedxml-20260925
Open

seonghobae wants to merge 1 commit into
mainfrom
fix/trusted-uv-quality-defusedxml-20260925

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Problem

The `Python 3.14 full quality gate` job in `trusted-uv-materializer-quality-ci.yml` runs the full `pytest tests` suite, but it installed only `requirements-opencode-review-ci-hashes.txt`. The Noema document tests import `defusedxml`, so test collection fails on main (run 36332466999: `ModuleNotFoundError: No module named 'defusedxml'` in `test_noema_document_review_context.py`, `test_noema_preflight_capacity.py`, …).

Change

  • Install `requirements-noema-document-ci-hashes.txt` (hash-locked `defusedxml==0.7.1`) alongside the OpenCode review lock, include it in the pip cache key, and add it to the trigger paths. This matches `agent-review-runtime-quality-ci.yml`.
  • The contract test `tests/test_trusted_uv_materializer_quality_workflow_contract.py` now pins the install command, the trigger path, and the presence of the lock.

Evidence

  • Red: against main's workflow, 2 contract tests fail.
  • Green: with the change, the contract tests pass, along with the Noema tests that previously failed at collection (108 passed locally in a 3.14 env with both locks installed).

Developer experience: the trusted uv gate on main stops failing for a reason unrelated to the materializer.
User experience: no user-facing change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01H8Nf6C8Cs5zDAF8z7MrgoB

The full central test step collects the Noema document tests, which
import defusedxml. The gate installed only the OpenCode review lock, so
main runs failed at collection with ModuleNotFoundError. Install the
hash-locked Noema document lock alongside it, matching the agent review
runtime quality workflow, and pin the contract in its test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H8Nf6C8Cs5zDAF8z7MrgoB
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b9f7f2d5-bd4f-4bb0-8175-67ee3fcee50d

📥 Commits

Reviewing files that changed from the base of the PR and between 3295c25 and a45eae6.

📒 Files selected for processing (2)
  • .github/workflows/trusted-uv-materializer-quality-ci.yml
  • tests/test_trusted_uv_materializer_quality_workflow_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Queue-wait RCA (2026-09-28 16:07 UTC): every check on head a45eae6 has been queued since 15:10 UTC. None have failed.

  • Repo-wide: 957 runs queued, 7 in progress, and the in-progress slots are mostly multi-hour Strix scans. Jobs wait for ubuntu-latest, so this is the hosted plan's concurrent-job ceiling, the residual docs(doctoring): plan-ceiling owner brief (post-#2252 residual) #2258 already identifies (options A/B are owner billing decisions).
  • Arrival hygiene (option C) is not a meaningful lever right now: only 19 of 422 queued PR-event runs belong to superseded heads or closed PRs. The arrival driver is the ~364 open PRs.
  • This PR has no local blocker. Once the queue admits it, Python 3.14 full quality gate should stop failing at defusedxml collection, as it does on main (run 36332466999). The OpenCode review and scheduler then provide the independent approval and the merge.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant