Skip to content

Add debugpy release agent - #2062

Merged
Rich Chiodo (rchiodo) merged 7 commits into
microsoft:mainfrom
rchiodo:rchiodo/add-debugpy-release-agent
Aug 11, 2026
Merged

Rich Chiodo (rchiodo) merged 7 commits into
microsoft:mainfrom
rchiodo:rchiodo/add-debugpy-release-agent

Conversation

@rchiodo

Copy link
Copy Markdown
Contributor

Summary

  • add a user-invocable Debugpy Release agent
  • automate version selection, tagging, signed internal builds, PyPI verification, and GitHub release creation
  • discover internal pipeline configuration at runtime so confidential infrastructure details are not committed
  • enforce ordering and safety gates for partial or failed releases

Automate the guarded tag, signed build, PyPI publication, and GitHub release workflow without committing internal infrastructure details.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
@rchiodo
Rich Chiodo (rchiodo) requested a review from a team as a code owner August 10, 2026 23:10
@StellaHuang95

Copy link
Copy Markdown
Contributor

🔒 Automated review in progress — Stella Huang (@StellaHuang95) is auto-reviewing this PR.

Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
@StellaHuang95 Stella Huang (StellaHuang95) added the review-auto:changes-requested Automated review: posted blocking findings to address. label Aug 10, 2026
Add deterministic state reconciliation, resumable releases, required-check discovery, exact build pinning, bounded PyPI verification, and backport-aware latest handling. Allow private pipeline URLs through environment variables.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
@rchiodo

Copy link
Copy Markdown
Contributor Author

Addressed all six review findings in c75f78b:

  • deterministic reconciliation when GitHub and PyPI disagree
  • required-check discovery through repository rules/branch protection
  • resume/finalize support for partial releases
  • exact Phase 3 build ID pinning, with abort conditions when pinning is unavailable
  • exact normalized package version plus bounded PyPI polling
  • conditional --latest handling for backports

I also added support for direct internal pipeline locations via DEBUGPY_INTERNAL_BUILD_PIPELINE_URL and DEBUGPY_INTERNAL_RELEASE_PIPELINE_URL. Their values remain outside the public repository and are validated against the authenticated Azure DevOps scope at runtime.

Comment thread .github/agents/debugpy-release.agent.md
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

@StellaHuang95 Stella Huang (StellaHuang95) added review-auto:approved Automated review: no blocking findings (approval posted). and removed review-auto:changes-requested Automated review: posted blocking findings to address. labels Aug 10, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

Make local-only tag recovery re-derivable, prevent republishing after PyPI succeeds, and preserve the Phase 1 latest-selection baseline across resumed runs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Comment thread .github/agents/debugpy-release.agent.md
Comment thread .github/agents/debugpy-release.agent.md Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

Keep local-tag recovery within the full preflight and recompute the latest-selection baseline deterministically for each invocation, with a final release-set recheck.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Comment thread .github/agents/debugpy-release.agent.md
Comment thread .github/agents/debugpy-release.agent.md

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

Separate local and remote tag state during recovery and exclude the verified in-flight PyPI version from final concurrency reconciliation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md Outdated
Comment thread .github/agents/debugpy-release.agent.md
@StellaHuang95 Stella Huang (StellaHuang95) added review-auto:changes-requested Automated review: posted blocking findings to address. and removed review-auto:approved Automated review: no blocking findings (approval posted). labels Aug 11, 2026
Use host-provided tools, centralize recovery inventory, define backports, unify in-flight PyPI state, and clean temporary artifacts on all exit paths.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Phase 5; its expected PyPI-only state must not be treated as a new incomplete
release. If any other release state changed, repeat Phase 1 reconciliation
with the in-flight version explicitly marked as expected and update the
invocation's latest-selection baseline before continuing. For backports and

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning · Non-blocking recommendation

When resuming a backport after PyPI has already published the verified in-flight version, this check can compare the target against itself and reject a valid Phase 6 completion. Exclude the verified in-flight version here as step 2 does, or explicitly evaluate this ordering check against the pre-release Phase 1 baseline. [verified]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

@StellaHuang95 Stella Huang (StellaHuang95) added review-auto:approved Automated review: no blocking findings (approval posted). and removed review-auto:changes-requested Automated review: posted blocking findings to address. labels Aug 11, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

@rchiodo
Rich Chiodo (rchiodo) merged commit 6dd019a into microsoft:main Aug 11, 2026
20 of 23 checks passed
shrewd-laidback palace (736-c41-2c1-e464fc974) pushed a commit to Swiss-Armed-Forces/Loom that referenced this pull request Sep 20, 2026
This MR contains the following updates:

| Package | Type | Update | Change | OpenSSF |
|---|---|---|---|---|
| [debugpy](https://aka.ms/debugpy) ([source](https://github.com/microsoft/debugpy)) | dev | patch | `1.8.21` → `1.8.22` | [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/microsoft/debugpy/badge)](https://securityscorecards.dev/viewer/?uri=github.com/microsoft/debugpy) |

---

### Release Notes

<details>
<summary>microsoft/debugpy (debugpy)</summary>

### [`v1.8.22`](https://github.com/microsoft/debugpy/releases/tag/v1.8.22): debugpy v1.8.22

[Compare Source](microsoft/debugpy@v1.8.21...v1.8.22)

##### Fixes

- Fix invalid type annotation in test\_pydev\_monkey comprehension by [@&#8203;pdepetro](https://github.com/pdepetro) in [#&#8203;2033](microsoft/debugpy#2033)
- Fix PEP 768 code injection SyntaxError when temp path contains backslashes by [@&#8203;rchiodo](https://github.com/rchiodo) with [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;2038](microsoft/debugpy#2038)
- Fix race between adapter connection publication and session attachment by [@&#8203;aperez](https://github.com/aperez) in [#&#8203;2049](microsoft/debugpy#2049)
- Fix debugger hang when expanding objects with blocking property getters ([#&#8203;2053](microsoft/debugpy#2053)) by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2055](microsoft/debugpy#2055)
- Fix duplicate stopped event when two threads hit a breakpoint at once by [@&#8203;aperez](https://github.com/aperez) in [#&#8203;2056](microsoft/debugpy#2056)
- Avoid exceptions in environment diagnostics by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2059](microsoft/debugpy#2059)
- Fix thread identity when the first traced call is another thread's is\_alive() by [@&#8203;aperez](https://github.com/aperez) in [#&#8203;2061](microsoft/debugpy#2061)
- Respect isolated mode when patching sys.path by [@&#8203;karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash) in [#&#8203;2050](microsoft/debugpy#2050)

##### Enhancements

- Add trigger\_exception\_handler() for post-mortem debugging of caught exceptions by [@&#8203;nshepperd](https://github.com/nshepperd) in [#&#8203;1996](microsoft/debugpy#1996)
- Add lldb attach-to-PID option for debugpy on Linux by [@&#8203;pdepetro](https://github.com/pdepetro) in [#&#8203;2052](microsoft/debugpy#2052)
- Populate hitBreakpointIds in the DAP stopped event by [@&#8203;aperez](https://github.com/aperez) in [#&#8203;2060](microsoft/debugpy#2060)
- Return the endpoint from listen() with the in-process adapter by [@&#8203;karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash) in [#&#8203;2051](microsoft/debugpy#2051)

##### Infrastructure work

- Add Dependabot configuration for pip and GitHub Actions by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2041](microsoft/debugpy#2041)
- Update vendored pydevd 3.4.1 -> 3.5.0 (maintenance refresh) by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2044](microsoft/debugpy#2044)
- Pin secure test dependency floors and drop EOL Python 3.9/3.8 by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2045](microsoft/debugpy#2045)
- Add more typing to debugpy and switch to 'standard' type checking mode by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;1637](microsoft/debugpy#1637)
- Add debugpy release agent by [@&#8203;rchiodo](https://github.com/rchiodo) in [#&#8203;2062](microsoft/debugpy#2062)
- Pin GitHub Actions to full-length commit SHAs by [@&#8203;danfiedler-msft](https://github.com/danfiedler-msft) in [#&#8203;2063](microsoft/debugpy#2063)
- Add python 3.15 to tests by [@&#8203;finnagin](https://github.com/finnagin) in [#&#8203;2069](microsoft/debugpy#2069)

Thanks to [@&#8203;pdepetro](https://github.com/pdepetro), [@&#8203;rchiodo](https://github.com/rchiodo), [@&#8203;nshepperd](https://github.com/nshepperd), [@&#8203;aperez](https://github.com/aperez), [@&#8203;karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash), [@&#8203;danfiedler-msft](https://github.com/danfiedler-msft), and [@&#8203;finnagin](https://github.com/finnagin) for the commits.

**Full Changelog**: <microsoft/debugpy@v1.8.21...v1.8.22>

</details>

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNSIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSJdfQ==-->

See merge request swiss-armed-forces/cyber-command/cea/loom!814
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review-auto:approved Automated review: no blocking findings (approval posted).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants