diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index 73da9ae5..a2b82cd6 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -25,6 +25,7 @@ Closes # - [ ] One concern per PR; unrelated changes are split out - [ ] `CHANGELOG.md` has an entry under `[Unreleased]` +- [ ] If `pyproject.toml` dependencies changed, `poetry lock` was run and the updated `poetry.lock` is committed - [ ] Documentation updated (`README.md`, `docs/`, `.env.example`, `CLAUDE.md`) where settings or commands changed - [ ] New settings default to current behaviour - [ ] If AI tools helped write this change, I reviewed every line and the hand-testing above is mine diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 33887d3f..2b9ed2cf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -31,8 +31,11 @@ jobs: path: .venv key: venv-${{ runner.os }}-3.11-${{ hashFiles('**/poetry.lock') }} + - name: Verify lockfile is up to date + run: poetry check --lock + - name: Install dependencies - run: poetry lock && poetry install + run: poetry install --no-interaction - name: Check formatting (black) run: poetry run black --check src tests @@ -67,8 +70,11 @@ jobs: path: .venv key: venv-${{ runner.os }}-3.11-${{ hashFiles('**/poetry.lock') }} + - name: Verify lockfile is up to date + run: poetry check --lock + - name: Install dependencies - run: poetry lock && poetry install + run: poetry install --no-interaction - name: Test run: make test diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 697f4369..8af7f05b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -32,6 +32,9 @@ jobs: path: .venv key: venv-${{ runner.os }}-3.11-${{ hashFiles('**/poetry.lock') }} + - name: Verify lockfile is up to date + run: poetry check --lock + - name: Install dependencies run: poetry install --no-interaction diff --git a/CHANGELOG.md b/CHANGELOG.md index 75a7bdf6..f51c5180 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Fixed +- **CI now catches lockfile drift**: the `lint` and `test` jobs ran `poetry lock && poetry install`, which regenerated `poetry.lock` in place. A `pyproject.toml` dependency change with a stale lock therefore passed every PR and failed only at release time, as it did for v1.7.0 (#196). Both jobs now verify the lock with `poetry check --lock` and install from the committed lock, so CI tests the dependency set that actually ships rather than resolving a fresh one on every run. + ## [1.7.0] - 2026-09-11 Released as a minor rather than a patch: the security fix below changes runtime diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 3d189471..a646eea2 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -95,6 +95,10 @@ five-layer security model. Read it before touching `src/security/` or - Tests for behaviour changes. `make test` and `make lint` pass. CI runs black, isort, flake8 and the test suite on every PR. +- **If you change dependencies, run `poetry lock` and commit the updated + `poetry.lock` in the same PR.** CI installs from the committed lock and + fails the build if the lock and `pyproject.toml` disagree, so a + `pyproject.toml` dependency change without a matching lock update goes red. - A line under `[Unreleased]` in `CHANGELOG.md`, in the Keep a Changelog style already used there. - Docs updated where a setting or command changed: `README.md`,