Skip to content

Support pySigma 2.0 - #16

Draft
cristianchiriac wants to merge 1 commit into
SigmaHQ:mainfrom
cristianchiriac:support-pysigma-2
Draft

cristianchiriac wants to merge 1 commit into
SigmaHQ:mainfrom
cristianchiriac:support-pysigma-2

Conversation

@cristianchiriac

Copy link
Copy Markdown

pySigma 2.0.0 was released yesterday. The backend currently requires pysigma>=1.5.1,<2.0, so it can't be installed alongside it.

Changes

  • pyproject.toml: pysigma>=2.0.0,<3.0. poetry.lock was regenerated with poetry lock. The only resolved changes are pysigma 1.5.1 → 2.0.0, the new google-re2 dependency, and removal of the 3.10-only exceptiongroup/tomli.
  • pySigma 2.0 requires Python ≥ 3.11 (pysigma (2.0.0) requires Python <4.0,>=3.11), so:
    • requires-python is now >=3.11,<4.0;
    • 3.10 is removed from the test matrix;
    • the "Build minimum supported SQLite" step now runs on the 3.11 job, so the minimum-SQLite tests still run in CI.
  • test_sqlite_cidr_ipv6_prefix_ending_in_zero_groups: pySigma 2.0 expands 2001:db8::/64 to the uncompressed prefix as well as the compressed one. The expected query is now field LIKE '2001:db8:0:0:%' ... OR field LIKE '2001:db8::%' .... The previous expectation is kept in the comment for context.
  • README requirements updated to match.

Testing: after poetry install (pySigma 2.0.0, Python 3.11), pytest gives 162 passed and 16 skipped. Without the test change, only test_sqlite_cidr_ipv6_prefix_ending_in_zero_groups fails. I found no other behavior differences in the test suite.

pySigma 2.0.0 was released on 2026-10-04. Raise the dependency to
pysigma>=2.0.0,<3.0 and refresh poetry.lock.

pySigma 2.0 requires Python 3.11, so drop 3.10 from requires-python and the
test matrix, and build the minimum supported SQLite on the 3.11 job.

pySigma 2.0 expands an IPv6 CIDR whose network ends in zero groups to both the
uncompressed and the compressed prefix, so 2001:db8::/64 now also matches
'2001:db8:0:0:%'. Update the expected query.
@cristianchiriac

Copy link
Copy Markdown
Author

Update: the red CI here is not caused by this change. pySigma 2.0.0 turned sigma into a regular package (it added sigma/__init__.py), so a plugin installed in editable mode, which is what poetry install does, can no longer be imported: ModuleNotFoundError: No module named 'sigma.backends...'. I reported and proposed a fix upstream in SigmaHQ/pySigma#584.

Correction to the description above: my local runs that passed used a non-editable install of this backend (pip install .), not plain poetry install. Sorry for the imprecise wording. I'm marking this as a draft until a pySigma release contains the fix, and will then refresh the lock file.

@cristianchiriac
cristianchiriac marked this pull request as draft October 5, 2026 16:31

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant