You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This repo was still on the legacy pipenv-based template (Pipfile, black, plain docker build, old shared CI/deploy workflows). It no longer conformed to the current MIT Libraries Python project spec.
How this addresses that need:
Replaced Pipfile/Pipfile.lock with pyproject.toml [project] / [dependency-groups] and a generated uv.lock.
Removed [tool.black]; bumped ruff target-version and Python to 3.13.
Rewrote Makefile targets to use uv run/uv sync/uv lock; dropped black/safety/*-apply targets in favor of lint/lint-fix/security.
Added CPU_ARCH, check-arch, docker-clean, and buildx-based dist-dev/publish-dev (secure --password-stdin login, no hardcoded --platform); applied the same fixes to the preserved stage targets.
Added sam-build/sam-invoke targets
Added tests/sam/template.yaml
Updated .pre-commit-config.yaml to pre-push stage with ruff-format/ruff-check hooks; removed black/pip-audit hooks.
Updated CI/deploy workflows to pull_request trigger, read-all/ id-token permissions, and the python-uv-shared-/ecr-multi-arch- shared workflows.
Updated Dockerfile to the python:3.13 Lambda base image with a uv-based dependency export/install flow.
Updated .gitignore and the PR template to match spec requirements.
Side effects of this change:
Local dev now requires uv instead of pipenv; contributors need to run make install fresh.
CI now triggers on pull_request instead of push.
.aws-architecture is still missing, so builds continue to fall back to linux/amd64 until that's added with Infra sign-off.
Why these changes are being introduced:
This repo was still on the legacy pipenv-based template (Pipfile,
black, plain `docker build`, old shared CI/deploy workflows). It no
longer conformed to the current MIT Libraries Python project spec.
How this addresses that need:
- Replaced Pipfile/Pipfile.lock with pyproject.toml [project] /
[dependency-groups] and a generated uv.lock.
- Removed [tool.black]; bumped ruff target-version and Python to 3.13.
- Rewrote Makefile targets to use `uv run`/`uv sync`/`uv lock`;
dropped black/safety/*-apply targets in favor of lint/lint-fix/security.
- Added CPU_ARCH, check-arch, docker-clean, and buildx-based
dist-dev/publish-dev (secure --password-stdin login, no hardcoded
--platform); applied the same fixes to the preserved stage targets.
- Added sam-build/sam-invoke targets (pending a tests/sam/template.yaml).
- Updated .pre-commit-config.yaml to pre-push stage with
ruff-format/ruff-check hooks; removed black/pip-audit hooks.
- Updated CI/deploy workflows to pull_request trigger, read-all/
id-token permissions, and the python-uv-shared-*/ecr-multi-arch-*
shared workflows.
- Updated Dockerfile to the python:3.13 Lambda base image with a
uv-based dependency export/install flow.
- Updated .gitignore and the PR template to match spec requirements.
Side effects of this change:
- Local dev now requires `uv` instead of `pipenv`; contributors need
to run `make install` fresh.
- CI now triggers on `pull_request` instead of `push`.
- `.aws-architecture` is still missing, so builds continue to fall
back to linux/amd64 until that's added with Infra sign-off.
- sam-build/sam-invoke targets exist but won't run until
tests/sam/template.yaml is added.
Relevant ticket(s):
TBD
Why these changes are being introduced:
The Makefile's sam-build/sam-invoke targets (added during the spec
alignment work) had no backing SAM template, so they couldn't run.
The spec requires Lambda projects to support local testing via SAM
in addition to the existing manual docker build/run/curl workflow.
How this addresses that need:
- Added tests/sam/template.yaml: an AWS::Serverless::Function resource
with PackageType: Image, pointing at the repo's Dockerfile via
DockerContext, with WORKSPACE=dev set to match the app's required
env var.
- Updated the Makefile's sam-invoke target to send a realistic
queryStringParameters payload (matching the example already in the
README) instead of the generic placeholder event.
Side effects of this change:
- Requires the AWS SAM CLI (`sam`) to be installed locally to use
make sam-build/make sam-invoke; installed here via `pipx install
aws-sam-cli` since brew isn't available on this Linux/WSL setup.
- Verified locally: `make sam-invoke` exits 0 and returns the expected
redirect response.
Relevant ticket(s):
Resolves:
See also:
Publish reads architecture tag before generating it
Makefile:149
This target reads .arch_tag, but unlike publish-dev it does not run any target that creates that ignored file. On a fresh checkout, ARCH_TAG is empty and the first two pushes use malformed image references. Make check-arch a prerequisite before reading the tag.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why these changes are being introduced:
This repo was still on the legacy pipenv-based template (Pipfile, black, plain
docker build, old shared CI/deploy workflows). It no longer conformed to the current MIT Libraries Python project spec.How this addresses that need:
uv run/uv sync/uv lock; dropped black/safety/*-apply targets in favor of lint/lint-fix/security.Side effects of this change:
uvinstead ofpipenv; contributors need to runmake installfresh.pull_requestinstead ofpush..aws-architectureis still missing, so builds continue to fall back to linux/amd64 until that's added with Infra sign-off.Includes new or updated dependencies?
YES
Changes expectations for external applications?
NO
related ticket:
https://mitlibraries.atlassian.net/browse/ENSY-553