You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is the workflow-catalog slice of #4719. A workflow catalog entry continues to advertise its current release in the existing top-level version, url, and optional sha256/requires fields. Customer-authored catalogs can also advertise historical releases in an optional releases map keyed by version, where each release has its own URL and SHA-256 digest and can declare its own requirements. Malformed, inconsistent, and duplicate histories raise workflow catalog validation errors.
WorkflowCatalog.get_workflow_info(id, version=None) returns the current or a selected exact release from the winning catalog source, and get_workflow_versions(id) lists its advertised versions. specify workflow add <id> --version <version> installs the selected release; specify workflow info <id> --versions displays the available versions. A missing historical release never falls through to a lower-priority catalog or substitutes current, and discovery-only catalogs stay non-installable. Installs validate the selected URL and redirects, downloaded SHA-256 (archive or YAML), workflow ID and version, and any declared release requirements before committing. Unqualified search/info/add/update and direct --from retain their established behavior. Workflow steps and bundle pin resolution are separate #4719 slices.
Testing
Tested locally with .venv/bin/specify workflow add --help and .venv/bin/specify workflow info --help (both new options present).
Ran focused tests from this worktree's .venv: 915 passed after rebasing onto current main (workflow catalog, command add/info/update, workflow regression suite, existing bundle delegation). Scoped Ruff and diff checks passed.
Tested with a separate sample project; catalog-backed install is exercised in CLI integration tests with a mocked download and a real workflow archive/YAML.
An earlier full-suite run on this worktree finished with 8,549 passed, 17 skipped, 64 failed. All 64 failures were in PowerShell tests with a runtime System.IO.FileLoadException; a representative failed test passed when rerun alone. The full suite was not rerun after the rebase; no PowerShell or integration code was changed by this PR.
AI Disclosure
I did not use AI assistance for this contribution
I did use AI assistance (fill in the disclosure below)
AI disclosure: GitHub Copilot (GPT-6 Sol, autonomous mode, session-default reasoning settings not exposed) generated the workflow-catalog implementation, tests, documentation, this PR description, and performed the checks listed above. This is agent-authored work; no human line-by-line review or testing is claimed.
Keep current workflow metadata at the top level while validating and selecting optional historical releases from the winning catalog. Verify the selected digest, requirements, ID, and version before installation, and expose available versions in workflow info.
Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Catalog entries with releases now validate their advertised current version and each historical key against the same X.Y.Z rule as workflow definitions. PEP 440-equivalent spelling remains accepted for the requested version, while the downloaded workflow must declare the advertised spelling for both YAML and archive installs.
workflow info <id> --versions now prints the winning catalog’s install policy, explicitly marking discovery-only versions as not installable. The policy and versions are read together from one winning catalog entry.
New regression tests failed before the fixes; the focused workflow and bundle-delegation suites now pass (925 tests). Scoped lint and diff checks pass. The earlier full-suite PowerShell runtime failures noted in the PR body were not rerun here.
Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode, session-default reasoning settings not exposed). Copilot generated this review-round code, tests, documentation, and comment, and ran the listed checks. Review conversations remain for reviewers to resolve.
Reproduce narrow Windows Rich console output and compare the validation message after normalizing whitespace, without weakening the exit or rollback assertions.
Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
New YAML requirement validation and several catalog-only option rejection branches lack required negative test coverage.
Review effort: Balanced Findings: None
Previously missed (2)
In code that hasn't changed since last review
Add negative test for mismatched YAML requires
src/specify_cli/workflows/_commands.py:1367
Add a negative YAML-install test for this branch. The existing requirements-mismatch case downloads an archive and exercises expected_requires in _install_workflow_package, while the new standalone-YAML comparison here is never entered. A .yml historical release whose catalog requires differs from the downloaded definition should assert exit 1 and no registry/file commit, as required by the repository's positive-and-negative coverage rule.
Test --version rejection for all invalid source forms
src/specify_cli/workflows/command_add.py:54
Please cover each newly rejected source form here. The only invalid-scope test uses --from; there is no --version test for a bare URL, an existing local path, or --dev, even though these are separate branches and the documentation now promises that all are rejected. A parametrized CLI test would prevent one route from accidentally bypassing catalog-only selection.
CI follow-up at commit 92f719b0: the prior Windows 3.13 pytest failure was a test assertion against Rich output wrapping between “requested” and “workflow ID,” not an install failure. The test now forces a narrow console and checks the same error after whitespace normalization, retaining the exit-status and no-install assertions. It failed locally before the fix and passes afterward; 925 focused tests and scoped Ruff checks pass locally. The new CI run is green across Windows, macOS, and Ubuntu (Python 3.13/3.14), Ruff, markdownlint, shellcheck, CodeQL, and the remaining applicable checks.
Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode; session-default reasoning settings not exposed). Copilot investigated the CI logs, generated the test change and this comment, and ran the listed validation.
Exercise mismatched requirements in standalone YAML releases and reject exact-version selection for URL, local-file, local-directory, and dev sources before download or install.
Assisted-by: GitHub Copilot (model: GPT-6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Follow-up for review 5353318310 at 7644fbcc: both previously missed Low coverage requests are now addressed. The new standalone .yml historical-release test supplies valid downloaded bytes with a mismatched catalog requires and verifies exit 1, no registry entry, and no installed file. A parametrized CLI test covers --version rejection for a bare URL, an existing YAML file, an existing directory, and --dev, asserting no download or install. This is test-only; production behavior was already present. The focused workflow and bundle-delegation suites pass (930 tests), and Ruff check/format pass. Replacement CI is running.
Posted on behalf of @mnriem by GitHub Copilot (GPT-6 Sol, autonomous mode; session-default reasoning settings not exposed). Copilot added these tests, ran validation, and generated this comment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
triage-can-waitVerdict: valid and in-scope but deprioritized; held behind the evidence gate
2 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This is the workflow-catalog slice of #4719. A workflow catalog entry continues to advertise its current release in the existing top-level
version,url, and optionalsha256/requiresfields. Customer-authored catalogs can also advertise historical releases in an optionalreleasesmap keyed by version, where each release has its own URL and SHA-256 digest and can declare its own requirements. Malformed, inconsistent, and duplicate histories raise workflow catalog validation errors.WorkflowCatalog.get_workflow_info(id, version=None)returns the current or a selected exact release from the winning catalog source, andget_workflow_versions(id)lists its advertised versions.specify workflow add <id> --version <version>installs the selected release;specify workflow info <id> --versionsdisplays the available versions. A missing historical release never falls through to a lower-priority catalog or substitutes current, and discovery-only catalogs stay non-installable. Installs validate the selected URL and redirects, downloaded SHA-256 (archive or YAML), workflow ID and version, and any declared release requirements before committing. Unqualified search/info/add/update and direct--fromretain their established behavior. Workflow steps and bundle pin resolution are separate #4719 slices.Testing
.venv/bin/specify workflow add --helpand.venv/bin/specify workflow info --help(both new options present)..venv: 915 passed after rebasing onto currentmain(workflow catalog, command add/info/update, workflow regression suite, existing bundle delegation). Scoped Ruff and diff checks passed.An earlier full-suite run on this worktree finished with 8,549 passed, 17 skipped, 64 failed. All 64 failures were in PowerShell tests with a runtime
System.IO.FileLoadException; a representative failed test passed when rerun alone. The full suite was not rerun after the rebase; no PowerShell or integration code was changed by this PR.AI Disclosure
AI disclosure: GitHub Copilot (GPT-6 Sol, autonomous mode, session-default reasoning settings not exposed) generated the workflow-catalog implementation, tests, documentation, this PR description, and performed the checks listed above. This is agent-authored work; no human line-by-line review or testing is claimed.