Skip to content

Pin ruff version in the lint workflow - #23

Merged
martinlocklear merged 1 commit into
mainfrom
martinlocklear/cursor/pin-ruff-lint-ci-drift
Jul 27, 2026
Merged

martinlocklear merged 1 commit into
mainfrom
martinlocklear/cursor/pin-ruff-lint-ci-drift

Conversation

@martinlocklear

Copy link
Copy Markdown
Contributor

Human note - written by Martin, verbatim, not AI-generated:

A PR I was working on went red based on which ruff version is running. This pins that version so that it's deterministic.

(I really just threw a robot at this - didn't look much closer. This change seems relatively low risk)


[authored by Cursor]

Summary

  • Pin astral-sh/ruff-action@v4.0.0 to version: '0.15.22' on both the check and format --check steps in .github/workflows/lint.yml.

Motivation

The action ran unpinned with no in-repo ruff config, so CI installed the newest ruff at run time. ruff 0.16.0 turned lint red across the repo on pre-existing code (7 findings) that 0.15.22 passed. Pinning makes the check deterministic - a ruff release can no longer break every PR's lint on its own.

Out of scope: adopting 0.16.0's stricter rules (fixing the 7 findings) or adding an in-repo ruff config; either can follow.

Test plan

  • ruff check .github/scripts and ruff format --check .github/scripts clean at 0.15.22
  • actionlint clean on the workflow
  • CI Python (ruff) green on the PR

Tracked in INT-813.
Background: plan doc.

The ruff-action step ran unpinned with no in-repo ruff config, so CI
installed the newest ruff at run time. A later ruff release then failed
lint on unchanged code across the repo. Pin the ruff binary to a
known-good version so the check is deterministic and a future release
cannot turn lint red on its own.

[authored by Cursor]

Co-authored-by: Cursor <cursoragent@cursor.com>
@martinlocklear

Copy link
Copy Markdown
Contributor Author

[authored by Cursor]

While addressing review feedback on a sibling PR (trufflesecurity/.github#22), its lint check went red although the change was clean. Root cause: the Lint workflow's ruff-action runs unpinned with no in-repo ruff config, installing the latest ruff at run time; ruff 0.16.0 (released after that PR opened) enabled new default rules that flag 7 pre-existing findings repo-wide. This PR pins ruff to 0.15.22 (last known-good) so lint is deterministic.

Key decisions

  • Pin the version rather than fix the 7 findings now: smallest change that restores green and stops future drift.
  • Pin at the action level (version: input) rather than adding a config file: minimal, single-file.

Alternatives considered

  • Fix all 7 findings and pin to 0.16.0: larger, unrelated code churn.
  • Add a ruff.toml / pyproject config: more robust long-term but broader; deferred.

Background: pin-ruff-lint-ci-drift plan doc.

@martinlocklear
martinlocklear marked this pull request as ready for review July 27, 2026 14:29
@martinlocklear
martinlocklear requested a review from a team July 27, 2026 14:29
@martinlocklear
martinlocklear merged commit 52d6c3b into main Jul 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants