chore(ci): bump the rhiza pin to v1.3.3 - #70
Merged
Merged
Conversation
v1.3.2's generate-matrix job is broken: it runs build-and-inspect-python-package v2.18.0, whose twine 6 rejects the Metadata-Version: 2.5 that hatchling now writes, so the job that gates all of (RHIZA) CI dies before anything else runs. Jebel-Quant/rhiza#1497 moves BAIPP to v3.0.1 (twine 7, which understands 2.5) and shipped in v1.3.3.
Contributor
There was a problem hiding this comment.
Pull request overview
Updates this repository’s GitHub Actions reusable-workflow pins to jebel-quant/rhiza@v1.3.3 to resolve CI breakage caused by dependency drift (twine 6 failing on Python wheel Metadata-Version: 2.5), allowing the (RHIZA) CI pipeline to proceed again.
Changes:
- Bump all
jebel-quant/rhiza/.github/workflows/*references fromv1.3.2tov1.3.3across the repo’s workflow entrypoints. - Restore CI viability for
ci / generate-matrix(and therefore downstream RHIZA CI jobs) by pulling in Rhiza’s BAIPP/twine update.
Reviewed changes
Copilot reviewed 10 out of 10 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/rhiza_weekly.yml | Bumps reusable workflow pin to v1.3.3 for weekly maintenance workflow. |
| .github/workflows/rhiza_scorecard.yml | Bumps reusable workflow pin to v1.3.3 for Scorecard workflow. |
| .github/workflows/rhiza_paper.yml | Bumps reusable workflow pin to v1.3.3 for paper/docs workflow. |
| .github/workflows/rhiza_mutation.yml | Bumps reusable workflow pin to v1.3.3 for mutation testing workflow. |
| .github/workflows/rhiza_marimo.yml | Bumps reusable workflow pin to v1.3.3 for marimo workflow. |
| .github/workflows/rhiza_fuzzing.yml | Bumps reusable workflow pin to v1.3.3 for fuzzing workflow. |
| .github/workflows/rhiza_codeql.yml | Bumps reusable workflow pin to v1.3.3 for CodeQL workflow. |
| .github/workflows/rhiza_ci.yml | Bumps reusable workflow pin to v1.3.3 for main CI workflow. |
| .github/workflows/rhiza_book.yml | Bumps reusable workflow pin to v1.3.3 for book/docs workflow. |
| .github/workflows/rhiza_benchmark.yml | Bumps reusable workflow pin to v1.3.3 for benchmark workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why CI is red
ci / generate-matrixis failing here, on PRs and onmain:hatchling now stamps
Metadata-Version: 2.5into wheels. The reusable workflow atv1.3.2runsbuild-and-inspect-python-package@v2.18.0, whose twine 6 does not know metadata 2.5 and hard-fails.generate-matrixgates every other job in(RHIZA) CI, so nothing downstream of it ran.Nothing in this repo changed — this is dependency drift, and it blocked the open dependabot PRs here.
The fix
jebel-quant/rhiza#1497 moved BAIPP to v3.0.1, which ships twine 7 with metadata 2.5 support, and it shipped in v1.3.3. This moves every
jebel-quant/rhiza/…pin here fromv1.3.2tov1.3.3.Verified against a wheel built from this fleet: twine 6 →
InvalidDistribution, twine 7 →PASSED.v1.3.3 also carries a licence-gate fix and moves bandit's scan scope into
.banditso external analysers agree with CI.🤖 Generated with Claude Code