:wave: With all of the supply chain issues floati...
# general
c
šŸ‘‹ With all of the supply chain issues floating around I'm keen to specify
resolves_to_uploaded_prior_to
in my company's repo to ensure that lockfiles are typically at least 7 days old. We also use security scanning with snyk and that typically means we have to use the latest dependency to get around a vulnerability. uv has an
exclude-newer
setting which pip lacks, that'd allow us to overrule the 7 days rule on a per-package basis. Has there been any thought put into this? I think for now I'll just default to 7 days but recommend bypassing it for all dependencies when necessary. I'm happy to contribute code for this, however it makes sense to discuss it first.
w
I think we'll need to stabilize our uv lockfiles (have you tested them out, and if so, how's it working?) Then we can start getting features up and running, as there are a couple of features not at parity. I don't think our uv resolution yet uses custom configs either
However, it'll be stability, then config
c
I just mucked around with it today, seemed to work without issue (although moving over to the pre-release pants was giving os.fork warnings). Really happy to see this functionality. I think for now I'll keep my repo on the PEX lockfiles for now and will just ask people to temporarily relax the default "uploaded prior to" rule if they have a specific security issue they need to patch.
w
although moving over to the pre-release pants was giving os.fork warnings
Ugh. Yeah, one of our deps needs to be updated, or we need to hide the warning.
I just mucked around with it today, seemed to work without issue
šŸ‘ Thanks for testing this out! In this pre-release stage is when we want to find issues with the resolver.
rc0
should be going out today, and then I want to keep an eye on any blockers (however, since it's an opt-in feature, not sure there will be)
c
I should clarify that I only tested the UV lockfile generation mechanism, haven't touched the new uploaded_prior_to stuff
w
That's fine, I meant the UV work - the more eyeballs we get now, the better
h
+1 for
exclude-newer
support. @wide-midnight-78598 Is there a ticket for these UV features? I’d like to have a look if possible