Skip to content

Align repo with Python project spec (uv migration) - #13

Merged
adamshire123 merged 3 commits into
mainfrom
align-with-spec
Sep 30, 2026
Merged

adamshire123 merged 3 commits into
mainfrom
align-with-spec

Conversation

@adamshire123

@adamshire123 adamshire123 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Why these changes are being introduced:

This repo was still on the legacy pipenv-based template (Pipfile, black, plain docker build, old shared CI/deploy workflows). It no longer conformed to the current MIT Libraries Python project spec.

How this addresses that need:

  • Replaced Pipfile/Pipfile.lock with pyproject.toml [project] / [dependency-groups] and a generated uv.lock.
  • Removed [tool.black]; bumped ruff target-version and Python to 3.13.
  • Rewrote Makefile targets to use uv run/uv sync/uv lock; dropped black/safety/*-apply targets in favor of lint/lint-fix/security.
  • Added CPU_ARCH, check-arch, docker-clean, and buildx-based dist-dev/publish-dev (secure --password-stdin login, no hardcoded --platform); applied the same fixes to the preserved stage targets.
  • Added sam-build/sam-invoke targets
  • Added tests/sam/template.yaml
  • Updated .pre-commit-config.yaml to pre-push stage with ruff-format/ruff-check hooks; removed black/pip-audit hooks.
  • Updated CI/deploy workflows to pull_request trigger, read-all/ id-token permissions, and the python-uv-shared-/ecr-multi-arch- shared workflows.
  • Updated Dockerfile to the python:3.13 Lambda base image with a uv-based dependency export/install flow.
  • Updated .gitignore and the PR template to match spec requirements.

Side effects of this change:

  • Local dev now requires uv instead of pipenv; contributors need to run make install fresh.
  • CI now triggers on pull_request instead of push.
  • .aws-architecture is still missing, so builds continue to fall back to linux/amd64 until that's added with Infra sign-off.

Includes new or updated dependencies?

YES

Changes expectations for external applications?

NO

related ticket:
https://mitlibraries.atlassian.net/browse/ENSY-553

Why these changes are being introduced:
This repo was still on the legacy pipenv-based template (Pipfile,
black, plain `docker build`, old shared CI/deploy workflows). It no
longer conformed to the current MIT Libraries Python project spec.

How this addresses that need:
- Replaced Pipfile/Pipfile.lock with pyproject.toml [project] /
  [dependency-groups] and a generated uv.lock.
- Removed [tool.black]; bumped ruff target-version and Python to 3.13.
- Rewrote Makefile targets to use `uv run`/`uv sync`/`uv lock`;
  dropped black/safety/*-apply targets in favor of lint/lint-fix/security.
- Added CPU_ARCH, check-arch, docker-clean, and buildx-based
  dist-dev/publish-dev (secure --password-stdin login, no hardcoded
  --platform); applied the same fixes to the preserved stage targets.
- Added sam-build/sam-invoke targets (pending a tests/sam/template.yaml).
- Updated .pre-commit-config.yaml to pre-push stage with
  ruff-format/ruff-check hooks; removed black/pip-audit hooks.
- Updated CI/deploy workflows to pull_request trigger, read-all/
  id-token permissions, and the python-uv-shared-*/ecr-multi-arch-*
  shared workflows.
- Updated Dockerfile to the python:3.13 Lambda base image with a
  uv-based dependency export/install flow.
- Updated .gitignore and the PR template to match spec requirements.

Side effects of this change:
- Local dev now requires `uv` instead of `pipenv`; contributors need
  to run `make install` fresh.
- CI now triggers on `pull_request` instead of `push`.
- `.aws-architecture` is still missing, so builds continue to fall
  back to linux/amd64 until that's added with Infra sign-off.
- sam-build/sam-invoke targets exist but won't run until
  tests/sam/template.yaml is added.

Relevant ticket(s):
TBD

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Make targets can preserve stale Pipenv hooks, deploy stale image tags, and report success after incomplete image publication.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Migrates the repository from Pipenv/Python 3.12 to the current uv-based Python 3.13 project specification.

Changes:

  • Replaces Pipenv and Black with uv, Ruff, and pyproject.toml.
  • Modernizes Docker and multi-architecture deployment workflows.
  • Adds updated hooks, SAM commands, and repository metadata.
File Description
pyproject.toml Defines project dependencies and Python 3.13 tooling.
uv.lock Locks production and development dependencies.
Pipfile Removes legacy Pipenv configuration.
Pipfile.lock Removes the legacy dependency lock.
Makefile Migrates development and deployment commands to uv/buildx.
Dockerfile Builds the Lambda image with Python 3.13 and uv.
.python-version Selects Python 3.13.
.pre-commit-config.yaml Replaces Pipenv/Black hooks with uv/Ruff hooks.
.gitignore Ignores buildx and SAM artifacts.
.github/​workflows/​ci.yml Uses shared uv CI workflows.
.github/​workflows/​dev-build.yml Uses multi-architecture development deployment.
.github/​workflows/​stage-build.yml Uses multi-architecture staging deployment.
.github/​workflows/​prod-promote.yml Uses multi-architecture production promotion.
.github/​pull-request-template.md Updates code-review guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Makefile
Comment thread Makefile
Comment thread Makefile
Why these changes are being introduced:
The Makefile's sam-build/sam-invoke targets (added during the spec
alignment work) had no backing SAM template, so they couldn't run.
The spec requires Lambda projects to support local testing via SAM
in addition to the existing manual docker build/run/curl workflow.

How this addresses that need:
- Added tests/sam/template.yaml: an AWS::Serverless::Function resource
  with PackageType: Image, pointing at the repo's Dockerfile via
  DockerContext, with WORKSPACE=dev set to match the app's required
  env var.
- Updated the Makefile's sam-invoke target to send a realistic
  queryStringParameters payload (matching the example already in the
  README) instead of the generic placeholder event.

Side effects of this change:
- Requires the AWS SAM CLI (`sam`) to be installed locally to use
  make sam-build/make sam-invoke; installed here via `pipx install
  aws-sam-cli` since brew isn't available on this Linux/WSL setup.
- Verified locally: `make sam-invoke` exits 0 and returns the expected
  redirect response.

Relevant ticket(s):

Resolves:
See also:

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Manual publish targets can conceal failures, and architecture-specific images are not consistently selected during Lambda updates.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Publish reads architecture tag before generating it

Makefile:149

This target reads .arch_tag, but unlike publish-dev it does not run any target that creates that ignored file. On a fresh checkout, ARCH_TAG is empty and the first two pushes use malformed image references. Make check-arch a prerequisite before reading the tag.

@adamshire123

Copy link
Copy Markdown
Contributor Author

@ghukill I don't understand any of Copilot's recommended changes.

@ghukill ghukill left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! If it runs, it runs. Can't see anything wrong with the pipenv --> uv migration.

@adamshire123
adamshire123 merged commit 1cae40e into main Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants