From 0e07748bf1fd45926b18018498d4a4f4e50173c8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?P=E5=B0=8F=E4=BA=8C?= Date: Sun, 4 Oct 2026 15:19:20 +0800 Subject: [PATCH 1/2] ci: pin ruff and fix lint so master validates again CI installed an unpinned ruff, so a new ruff release (UP017, B905) has failed every master and PR run since 2026-09-16. Pin ruff in the dev lock (upgrades now arrive via dependabot) and fix the three findings without changing behavior. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .github/workflows/validate.yml | 2 +- requirements-dev.lock.txt | 1 + tools/claim_receipt.py | 4 ++-- tools/verify_courses.py | 3 ++- 4 files changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index c7862b0..667eaa4 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -36,7 +36,7 @@ jobs: - name: Install dependencies and dev tools run: | uv venv --python ${{ matrix.python-version }} - uv pip install -r requirements-dev.lock.txt ruff + uv pip install -r requirements-dev.lock.txt - name: Lint with ruff run: .venv/bin/ruff check . diff --git a/requirements-dev.lock.txt b/requirements-dev.lock.txt index 9d5b0a2..d204eb5 100644 --- a/requirements-dev.lock.txt +++ b/requirements-dev.lock.txt @@ -9,6 +9,7 @@ Pygments==2.21.0 pytest==9.1.1 referencing==0.37.0 rpds-py==2026.6.3 +ruff==0.16.9 contourpy==1.4.0 cycler==0.12.1 fonttools==4.65.0 diff --git a/tools/claim_receipt.py b/tools/claim_receipt.py index 6ddf0a3..53085d8 100644 --- a/tools/claim_receipt.py +++ b/tools/claim_receipt.py @@ -17,7 +17,7 @@ import hmac import json import secrets -from datetime import datetime, timezone +from datetime import UTC, datetime from pathlib import Path SECRET_ENV = "FLYPYTHON_CLAIM_SECRET" @@ -85,7 +85,7 @@ def make_receipt( }, "impl_sha256": impl_hash, "solution_match": (impl_hash == solution_hash) if solution_hash else False, - "created_at": datetime.now(timezone.utc).isoformat(timespec="milliseconds").replace("+00:00", "Z"), + "created_at": datetime.now(UTC).isoformat(timespec="milliseconds").replace("+00:00", "Z"), "nonce": secrets.token_hex(16), } receipt["sig"] = hmac.new( diff --git a/tools/verify_courses.py b/tools/verify_courses.py index 1cf4f96..e86093e 100644 --- a/tools/verify_courses.py +++ b/tools/verify_courses.py @@ -376,8 +376,9 @@ def check_shared_core(courses: list[Path]) -> list[str]: shapes.append(list(zip( re.findall(r'"id":\s*"(l\d+|capstone)"', verify), re.findall(r'"gate":\s*"([a-z-]+)"', verify), + strict=False, ))) - for member, shape in zip(members[1:], shapes[1:]): + for member, shape in zip(members[1:], shapes[1:], strict=True): if shape != shapes[0]: problems.append( f"core-group {group}: {member.name} checkpoint ids/gates differ from {members[0].name}" From 5661d6a4f1085aa6a064a21cf2e9a87c17287c55 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?P=E5=B0=8F=E4=BA=8C?= Date: Sun, 4 Oct 2026 15:23:04 +0800 Subject: [PATCH 2/2] ci: keep the dev lock installable on Python 3.11 contourpy 1.4.0 and numpy 2.5.3 require Python >=3.12, so the 3.11 CI job has failed at install since the lock landed while pyproject still declares >=3.11. Pin the newest 3.11-compatible releases via markers. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- requirements-dev.lock.txt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/requirements-dev.lock.txt b/requirements-dev.lock.txt index d204eb5..74ab52d 100644 --- a/requirements-dev.lock.txt +++ b/requirements-dev.lock.txt @@ -10,12 +10,14 @@ pytest==9.1.1 referencing==0.37.0 rpds-py==2026.6.3 ruff==0.16.9 -contourpy==1.4.0 +contourpy==1.4.0; python_version >= "3.12" +contourpy==1.3.3; python_version < "3.12" cycler==0.12.1 fonttools==4.65.0 kiwisolver==1.5.1 matplotlib==3.10.9 -numpy==2.5.3 +numpy==2.5.3; python_version >= "3.12" +numpy==2.4.6; python_version < "3.12" pandas==2.3.3 pillow==12.3.0 pyparsing==3.3.2