Skip to content

chore(ci): bump the rhiza pin to v1.3.3 - #70

Merged
tschm merged 1 commit into
mainfrom
chore/rhiza-v1.3.3-pin
Aug 11, 2026
Merged

tschm merged 1 commit into
mainfrom
chore/rhiza-v1.3.3-pin

Conversation

@tschm

@tschm tschm commented Aug 11, 2026

Copy link
Copy Markdown
Member

Why CI is red

ci / generate-matrix is failing here, on PRs and on main:

InvalidDistribution: Invalid distribution metadata: '2.5' is not a valid metadata version

hatchling now stamps Metadata-Version: 2.5 into wheels. The reusable workflow at v1.3.2 runs build-and-inspect-python-package@v2.18.0, whose twine 6 does not know metadata 2.5 and hard-fails. generate-matrix gates every other job in (RHIZA) CI, so nothing downstream of it ran.

Nothing in this repo changed — this is dependency drift, and it blocked the open dependabot PRs here.

The fix

jebel-quant/rhiza#1497 moved BAIPP to v3.0.1, which ships twine 7 with metadata 2.5 support, and it shipped in v1.3.3. This moves every jebel-quant/rhiza/… pin here from v1.3.2 to v1.3.3.

Verified against a wheel built from this fleet: twine 6 → InvalidDistribution, twine 7 → PASSED.

v1.3.3 also carries a licence-gate fix and moves bandit's scan scope into .bandit so external analysers agree with CI.

🤖 Generated with Claude Code

v1.3.2's generate-matrix job is broken: it runs build-and-inspect-python-package v2.18.0, whose twine 6 rejects the Metadata-Version: 2.5 that hatchling now writes, so the job that gates all of (RHIZA) CI dies before anything else runs. Jebel-Quant/rhiza#1497 moves BAIPP to v3.0.1 (twine 7, which understands 2.5) and shipped in v1.3.3.
Copilot AI lite review requested due to automatic review settings August 11, 2026 08:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates this repository’s GitHub Actions reusable-workflow pins to jebel-quant/rhiza@v1.3.3 to resolve CI breakage caused by dependency drift (twine 6 failing on Python wheel Metadata-Version: 2.5), allowing the (RHIZA) CI pipeline to proceed again.

Changes:

  • Bump all jebel-quant/rhiza/.github/workflows/* references from v1.3.2 to v1.3.3 across the repo’s workflow entrypoints.
  • Restore CI viability for ci / generate-matrix (and therefore downstream RHIZA CI jobs) by pulling in Rhiza’s BAIPP/twine update.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated no comments.

Show a summary per file
File Description
.github/workflows/rhiza_weekly.yml Bumps reusable workflow pin to v1.3.3 for weekly maintenance workflow.
.github/workflows/rhiza_scorecard.yml Bumps reusable workflow pin to v1.3.3 for Scorecard workflow.
.github/workflows/rhiza_paper.yml Bumps reusable workflow pin to v1.3.3 for paper/docs workflow.
.github/workflows/rhiza_mutation.yml Bumps reusable workflow pin to v1.3.3 for mutation testing workflow.
.github/workflows/rhiza_marimo.yml Bumps reusable workflow pin to v1.3.3 for marimo workflow.
.github/workflows/rhiza_fuzzing.yml Bumps reusable workflow pin to v1.3.3 for fuzzing workflow.
.github/workflows/rhiza_codeql.yml Bumps reusable workflow pin to v1.3.3 for CodeQL workflow.
.github/workflows/rhiza_ci.yml Bumps reusable workflow pin to v1.3.3 for main CI workflow.
.github/workflows/rhiza_book.yml Bumps reusable workflow pin to v1.3.3 for book/docs workflow.
.github/workflows/rhiza_benchmark.yml Bumps reusable workflow pin to v1.3.3 for benchmark workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@tschm
tschm merged commit 8ff2eb3 into main Aug 11, 2026
62 checks passed
@tschm
tschm deleted the chore/rhiza-v1.3.3-pin branch August 12, 2026 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants