Add debugpy release agent - #2062
Rich Chiodo (rchiodo) merged 7 commits into
Conversation
Automate the guarded tag, signed build, PyPI publication, and GitHub release workflow without committing internal infrastructure details. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
|
🔒 Automated review in progress — Stella Huang (@StellaHuang95) is auto-reviewing this PR. |
Add deterministic state reconciliation, resumable releases, required-check discovery, exact build pinning, bounded PyPI verification, and backport-aware latest handling. Allow private pipeline URLs through environment variables. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
|
Addressed all six review findings in c75f78b:
I also added support for direct internal pipeline locations via |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Stella Huang (StellaHuang95)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
Heejae Chang (heejaechang)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
Make local-only tag recovery re-derivable, prevent republishing after PyPI succeeds, and preserve the Phase 1 latest-selection baseline across resumed runs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Stella Huang (StellaHuang95)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
Keep local-tag recovery within the full preflight and recompute the latest-selection baseline deterministically for each invocation, with a final release-set recheck. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Stella Huang (StellaHuang95)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
Separate local and remote tag state during recovery and exclude the verified in-flight PyPI version from final concurrency reconciliation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
Use host-provided tools, centralize recovery inventory, define backports, unify in-flight PyPI state, and clean temporary artifacts on all exit paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaf32286-5971-44a3-ad1e-5fdbb2a89f8d
| Phase 5; its expected PyPI-only state must not be treated as a new incomplete | ||
| release. If any other release state changed, repeat Phase 1 reconciliation | ||
| with the in-flight version explicitly marked as expected and update the | ||
| invocation's latest-selection baseline before continuing. For backports and |
There was a problem hiding this comment.
Warning · Non-blocking recommendation
When resuming a backport after PyPI has already published the verified in-flight version, this check can compare the target against itself and reject a valid Phase 6 completion. Exclude the verified in-flight version here as step 2 does, or explicitly evaluate this ordering check against the pre-release Phase 1 baseline. [verified]
Stella Huang (StellaHuang95)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
Heejae Chang (heejaechang)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
This MR contains the following updates: | Package | Type | Update | Change | OpenSSF | |---|---|---|---|---| | [debugpy](https://aka.ms/debugpy) ([source](https://github.com/microsoft/debugpy)) | dev | patch | `1.8.21` → `1.8.22` | [](https://securityscorecards.dev/viewer/?uri=github.com/microsoft/debugpy) | --- ### Release Notes <details> <summary>microsoft/debugpy (debugpy)</summary> ### [`v1.8.22`](https://github.com/microsoft/debugpy/releases/tag/v1.8.22): debugpy v1.8.22 [Compare Source](microsoft/debugpy@v1.8.21...v1.8.22) ##### Fixes - Fix invalid type annotation in test\_pydev\_monkey comprehension by [@​pdepetro](https://github.com/pdepetro) in [#​2033](microsoft/debugpy#2033) - Fix PEP 768 code injection SyntaxError when temp path contains backslashes by [@​rchiodo](https://github.com/rchiodo) with [@​Copilot](https://github.com/Copilot) in [#​2038](microsoft/debugpy#2038) - Fix race between adapter connection publication and session attachment by [@​aperez](https://github.com/aperez) in [#​2049](microsoft/debugpy#2049) - Fix debugger hang when expanding objects with blocking property getters ([#​2053](microsoft/debugpy#2053)) by [@​rchiodo](https://github.com/rchiodo) in [#​2055](microsoft/debugpy#2055) - Fix duplicate stopped event when two threads hit a breakpoint at once by [@​aperez](https://github.com/aperez) in [#​2056](microsoft/debugpy#2056) - Avoid exceptions in environment diagnostics by [@​rchiodo](https://github.com/rchiodo) in [#​2059](microsoft/debugpy#2059) - Fix thread identity when the first traced call is another thread's is\_alive() by [@​aperez](https://github.com/aperez) in [#​2061](microsoft/debugpy#2061) - Respect isolated mode when patching sys.path by [@​karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash) in [#​2050](microsoft/debugpy#2050) ##### Enhancements - Add trigger\_exception\_handler() for post-mortem debugging of caught exceptions by [@​nshepperd](https://github.com/nshepperd) in [#​1996](microsoft/debugpy#1996) - Add lldb attach-to-PID option for debugpy on Linux by [@​pdepetro](https://github.com/pdepetro) in [#​2052](microsoft/debugpy#2052) - Populate hitBreakpointIds in the DAP stopped event by [@​aperez](https://github.com/aperez) in [#​2060](microsoft/debugpy#2060) - Return the endpoint from listen() with the in-process adapter by [@​karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash) in [#​2051](microsoft/debugpy#2051) ##### Infrastructure work - Add Dependabot configuration for pip and GitHub Actions by [@​rchiodo](https://github.com/rchiodo) in [#​2041](microsoft/debugpy#2041) - Update vendored pydevd 3.4.1 -> 3.5.0 (maintenance refresh) by [@​rchiodo](https://github.com/rchiodo) in [#​2044](microsoft/debugpy#2044) - Pin secure test dependency floors and drop EOL Python 3.9/3.8 by [@​rchiodo](https://github.com/rchiodo) in [#​2045](microsoft/debugpy#2045) - Add more typing to debugpy and switch to 'standard' type checking mode by [@​rchiodo](https://github.com/rchiodo) in [#​1637](microsoft/debugpy#1637) - Add debugpy release agent by [@​rchiodo](https://github.com/rchiodo) in [#​2062](microsoft/debugpy#2062) - Pin GitHub Actions to full-length commit SHAs by [@​danfiedler-msft](https://github.com/danfiedler-msft) in [#​2063](microsoft/debugpy#2063) - Add python 3.15 to tests by [@​finnagin](https://github.com/finnagin) in [#​2069](microsoft/debugpy#2069) Thanks to [@​pdepetro](https://github.com/pdepetro), [@​rchiodo](https://github.com/rchiodo), [@​nshepperd](https://github.com/nshepperd), [@​aperez](https://github.com/aperez), [@​karandhaodiyal28-hash](https://github.com/karandhaodiyal28-hash), [@​danfiedler-msft](https://github.com/danfiedler-msft), and [@​finnagin](https://github.com/finnagin) for the commits. **Full Changelog**: <microsoft/debugpy@v1.8.21...v1.8.22> </details> --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNSIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSJdfQ==--> See merge request swiss-armed-forces/cyber-command/cea/loom!814
Summary