Skip to content

Avoid panic for invalid audit service URLs - #20374

Merged
konstin merged 2 commits into
mainfrom
codex/fix-audit-invalid-service-url
Jul 14, 2026
Merged

Avoid panic for invalid audit service URLs#20374
konstin merged 2 commits into
mainfrom
codex/fix-audit-invalid-service-url

Conversation

@konstin

@konstin konstin commented Jul 14, 2026

Copy link
Copy Markdown
Member

An invalid uv audit --service-url value currently panics during URL parsing. Parse the service URL in the CLI layer and return the standard argument error instead.

@zanieb

zanieb commented Jul 14, 2026

Copy link
Copy Markdown
Member

Shouldn't this happen in the CLI layer?

@astral-sh-bot

astral-sh-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown

uv test inventory changes

This PR changes the tests when compared with the latest main baseline.

  • Added tests: 1
  • Removed tests: 0
  • Changed suites: 1
uv::build: +1 / -0

Added:

  • uv::build::audit::audit_invalid_service_url

Removed: none

@woodruffw woodruffw added the uv audit Related to uv audit functionality label Jul 14, 2026
@konstin
konstin marked this pull request as ready for review July 14, 2026 20:07
@konstin

konstin commented Jul 14, 2026

Copy link
Copy Markdown
Member Author

Good catch, fixed.

@konstin
konstin requested a review from woodruffw July 14, 2026 20:17
@zanieb zanieb added bug Something isn't working preview Experimental behavior labels Jul 14, 2026
@konstin
konstin merged commit 4230bc4 into main Jul 14, 2026
57 checks passed
@konstin
konstin deleted the codex/fix-audit-invalid-service-url branch July 14, 2026 20:22
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 17, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.28` → `0.11.29` | `0.11.28` → `0.11.29` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.28` → `0.11.29` (astral-sh/uv)</summary>

### 0.11.29

## Release Notes

Released on 2026-07-15.

### Python

- Use gzip-compressed artifacts for PyPy downloads ([#20265](astral-sh/uv#20265))

### Enhancements

- Add JSON output to `uv tree` ([#19978](astral-sh/uv#19978))
- Add CUDA 13.2 as a supported PyTorch backend ([#20267](astral-sh/uv#20267))
- Prefer local artifacts over URLs when installing from `pylock.toml` ([#20393](astral-sh/uv#20393))
- Clarify diagnostics for unsatisfiable direct requirement ranges ([#20227](astral-sh/uv#20227))
- Include the selected project name in missing-extra errors ([#20358](astral-sh/uv#20358))

### Preview features

- Preserve extras and dependency-group conflict context when selecting locked project tools ([#20078](astral-sh/uv#20078))
- Split OSV audit queries that exceed the service's 1,000-package limit ([#20398](astral-sh/uv#20398))
- Apply OSV fixed-version information only to the matching package and ecosystem ([#20399](astral-sh/uv#20399))
- Skip the virtualenv distutils monkeypatch on Python 3.10 and later ([#20222](astral-sh/uv#20222))
- Report invalid `uv audit --service-url` values instead of panicking ([#20374](astral-sh/uv#20374))
- Include preview settings in the published SchemaStore schema ([#20304](astral-sh/uv#20304))

### Performance

- Reduce resolver work by widening selected versions across ranges without other known candidates ([#20115](astral-sh/uv#20115))
- Defer client and build setup for no-op `uv sync` operations ([#20364](astral-sh/uv#20364))
- Reuse workspace discovery during frozen syncs ([#20363](astral-sh/uv#20363))
- Reuse workspace discovery after resolving settings ([#20356](http… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 17, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.28` → `0.11.29` | `0.11.28` → `0.11.29` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.28` → `0.11.29` (astral-sh/uv)</summary>

### 0.11.29

## Release Notes

Released on 2026-07-15.

### Python

- Use gzip-compressed artifacts for PyPy downloads ([#20265](astral-sh/uv#20265))

### Enhancements

- Add JSON output to `uv tree` ([#19978](astral-sh/uv#19978))
- Add CUDA 13.2 as a supported PyTorch backend ([#20267](astral-sh/uv#20267))
- Prefer local artifacts over URLs when installing from `pylock.toml` ([#20393](astral-sh/uv#20393))
- Clarify diagnostics for unsatisfiable direct requirement ranges ([#20227](astral-sh/uv#20227))
- Include the selected project name in missing-extra errors ([#20358](astral-sh/uv#20358))

### Preview features

- Preserve extras and dependency-group conflict context when selecting locked project tools ([#20078](astral-sh/uv#20078))
- Split OSV audit queries that exceed the service's 1,000-package limit ([#20398](astral-sh/uv#20398))
- Apply OSV fixed-version information only to the matching package and ecosystem ([#20399](astral-sh/uv#20399))
- Skip the virtualenv distutils monkeypatch on Python 3.10 and later ([#20222](astral-sh/uv#20222))
- Report invalid `uv audit --service-url` values instead of panicking ([#20374](astral-sh/uv#20374))
- Include preview settings in the published SchemaStore schema ([#20304](astral-sh/uv#20304))

### Performance

- Reduce resolver work by widening selected versions across ranges without other known candidates ([#20115](astral-sh/uv#20115))
- Defer client and build setup for no-op `uv sync` operations ([#20364](astral-sh/uv#20364))
- Reuse workspace discovery during frozen syncs ([#20363](astral-sh/uv#20363))
- Reuse workspace discovery after resolving settings ([#20356](http… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 20, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `pipx:gh-action-pulse` | `latest` → `latest` | `0.5.1` → `1.0.0` |
| `prek` | `0.4.9` → `0.4.10` | `0.4.9` → `0.4.10` |
| `rumdl` | `0.2.34` → `0.2.36` | `0.2.34` → `0.2.36` |
| `tombi` | `1.2.0` → `1.2.3` | `1.2.0` → `1.2.3` |
| `uv` | `latest` → `latest` | `0.11.28` → `0.11.29` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.4.9` → `0.4.10` (j178/prek)</summary>

### v0.4.10

## Release Notes

Released on 2026-07-16.

### Enhancements

- Add PHP language support ([#2314](j178/prek#2314))
- Add freeze option to update settings ([#2323](j178/prek#2323))
- Add tag filters to update configuration ([#2354](j178/prek#2354))
- Identify 'mts' and 'cts' as TypeScript files ([#2209](j178/prek#2209))
- Publish Alpine Docker images ([#2352](j178/prek#2352))
- Support builtin and meta in try-repo ([#2350](j178/prek#2350))

### Bug fixes

- Fix Python discovery order ([#2348](j178/prek#2348))
- Fix Windows progress rendering ([#2328](j178/prek#2328))
- Preserve configured repo values for updates ([#2324](j178/prek#2324))
- Scope synthetic `GIT_WORK_TREE` to git commands ([#2356](j178/prek#2356))

### Documentation

- Expand common workflows guide ([#2351](j178/prek#2351))

### Contributors

- @​j178

## Install prek 0.4.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.10/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.10/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.4.10

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.4.10/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.4.10/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.… (truncated)

</details>
<details>
<summary>rumdl: `0.2.34` → `0.2.36` (rvben/rumdl)</summary>

### v0.2.35

### Added

- **cli**: honor --deny-config-warnings on the stdin path ([0f93ca5](rvben/rumdl@0f93ca5))
- **cli**: make --deny-config-warnings cover inline disable-comment rule names ([96d75f5](rvben/rumdl@96d75f5))
- **cli**: add --deny-config-warnings for config-file and CLI-flag problems ([5045daf](rvben/rumdl@5045daf))
- **reflow**: support breaking within emphasis spans ([2e8bded](rvben/rumdl@2e8bded))

### Fixed

- **reflow**: preserve non-breaking spaces and the space before French double punctuation ([f66021f](rvben/rumdl@f66021f))
- **cli**: walk directory arguments even when file paths are also passed ([d058273](rvben/rumdl@d058273))
- **lsp**: honor line anchors in goto-definition ([17a21e7](rvben/rumdl@17a21e7))
- **md077**: attribute middle-level continuation lines to their own list item ([c73763b](rvben/rumdl@c73763b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz.sha2… (truncated)

### v0.2.36

### Added

- **code-block-tools**: add shuck:format as a built-in shell formatter ([5b23261](rvben/rumdl@5b23261))

### Fixed

- **wasm**: stop double-converting already-character-based columns ([4178cdf](rvben/rumdl@4178cdf))
- **tests**: resolve String addition compilation errors under Rust 1.96 (#737) ([38f36cf](rvben/rumdl@38f36cf))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.36-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.co… (truncated)

</details>
<details>
<summary>tombi: `1.2.0` → `1.2.3` (tombi-toml/tombi)</summary>

### v1.2.1

<!-- Release notes generated using configuration in .github/release.yml at v1.2.1 -->

## What's Changed

In this release, we have updated the linter to issue a warning if it is unable to resolve elements such as $ref within a JSON Schema.

### 🐝 Bug Fixes
* Stabilize diagnostic collection names by @​ya7010 in tombi-toml/tombi#2000
* fix(lint): avoid false unused deprecated directive by @​ya7010 in tombi-toml/tombi#2001
* fix(vscode): make executable settings machine-scoped by @​ya7010 in tombi-toml/tombi#2002
* fix(validator): report schema resolution errors by @​ya7010 in tombi-toml/tombi#2010
* fix(glob): remove unused profile import by @​ya7010 in tombi-toml/tombi#2011
### 📦 Dependencies
* chore: resolve OSV code scanning alerts by @​ya7010 in tombi-toml/tombi#2004
### 🛠️ Other Changes
* docs: document deprecationMessage as non-standard support by @​ya7010 in tombi-toml/tombi#2003
* ci: pin OSV scanner workflow to existing action ref by @​ya7010 in tombi-toml/tombi#2005
* fix(validator): report not schema resolution errors by @​risu729 in tombi-toml/tombi#2007
* feat(diagnostic): integrate tombi-diagnostic for error reporting in validator by @​ya7010 in tombi-toml/tombi#2015
* Update error handling by @​ya7010 in tombi-toml/tombi#2016
* chore: change schemastore diagnostics level by @​ya7010 in tombi-toml/tombi#2017

## New Contributors
* @​risu729 made their first contribution in tombi-toml/tombi#2007

**Full Changelog**: tombi-toml/tombi@v1.2.0...v1.2.1

### v1.2.2

<!-- Release notes generated using configuration in .github/release.yml at v1.2.2 -->

## What's Changed
### 🐝 Bug Fixes
* ci: submit winget manifest leaf directory by @​ya7010 in tombi-toml/tombi#2018
### 📦 Dependencies
* chore: update package lock files for SunOS package by @​ya7010 in tombi-toml/tombi#2020
### 🛠️ Other Changes
* feat(dist): add x86_64-unknown-illumos binary distribution by @​sunshowers in tombi-toml/tombi#2014
* refactor(dist): infer CLI-only illumos builds by @​ya7010 in tombi-toml/tombi#2019

## New Contributors
* @​sunshowers made their first contribution in tombi-toml/tombi#2014

**Full Changelog**: tombi-toml/tombi@v1.2.1...v1.2.2

### v1.2.3

<!-- Release notes generated using configuration in .github/release.yml at v1.2.3 -->

## What's Changed
### 🦅 New Features
* Allow comment directives to suppress schema resolution warnings by @​ya7010 in tombi-toml/tombi#2023
### 🛠️ Other Changes
* ci: finalize illumos install checks by @​ya7010 in tombi-toml/tombi#2021
* fix(ci): preserve winget release metadata by @​ya7010 in tombi-toml/tombi#2022

**Full Changelog**: tombi-toml/tombi@v1.2.2...v1.2.3

</details>
<details>
<summary>uv: `0.11.28` → `0.11.29` (astral-sh/uv)</summary>

### 0.11.29

## Release Notes

Released on 2026-07-15.

### Python

- Use gzip-compressed artifacts for PyPy downloads ([#20265](astral-sh/uv#20265))

### Enhancements

- Add JSON output to `uv tree` ([#19978](astral-sh/uv#19978))
- Add CUDA 13.2 as a supported PyTorch backend ([#20267](astral-sh/uv#20267))
- Prefer local artifacts over URLs when installing from `pylock.toml` ([#20393](astral-sh/uv#20393))
- Clarify diagnostics for unsatisfiable direct requirement ranges ([#20227](astral-sh/uv#20227))
- Include the selected project name in missing-extra errors ([#20358](astral-sh/uv#20358))

### Preview features

- Preserve extras and dependency-group conflict context when selecting locked project tools ([#20078](astral-sh/uv#20078))
- Split OSV audit queries that exceed the service's 1,000-package limit ([#20398](astral-sh/uv#20398))
- Apply OSV fixed-version information only to the matching package and ecosystem ([#20399](astral-sh/uv#20399))
- Skip the virtualenv distutils monkeypatch on Python 3.10 and later ([#20222](astral-sh/uv#20222))
- Report invalid `uv audit --service-url` values instead of panicking ([#20374](astral-sh/uv#20374))
- Include preview settings in the published SchemaStore schema ([#20304](astral-sh/uv#20304))

### Performance

- Reduce resolver work by widening selected versions across ranges without other known candidates ([#20115](astral-sh/uv#20115))
- Defer client and build setup for no-op `uv sync` operations ([#20364](astral-sh/uv#20364))
- Reuse workspace discovery during frozen syncs ([#20363](astral-sh/uv#20363))
- Reuse workspace discovery after resolving settings ([#20356](http… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 20, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.28` → `0.11.29` | `0.11.28` → `0.11.29` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.28` → `0.11.29` (astral-sh/uv)</summary>

### 0.11.29

## Release Notes

Released on 2026-07-15.

### Python

- Use gzip-compressed artifacts for PyPy downloads ([#20265](astral-sh/uv#20265))

### Enhancements

- Add JSON output to `uv tree` ([#19978](astral-sh/uv#19978))
- Add CUDA 13.2 as a supported PyTorch backend ([#20267](astral-sh/uv#20267))
- Prefer local artifacts over URLs when installing from `pylock.toml` ([#20393](astral-sh/uv#20393))
- Clarify diagnostics for unsatisfiable direct requirement ranges ([#20227](astral-sh/uv#20227))
- Include the selected project name in missing-extra errors ([#20358](astral-sh/uv#20358))

### Preview features

- Preserve extras and dependency-group conflict context when selecting locked project tools ([#20078](astral-sh/uv#20078))
- Split OSV audit queries that exceed the service's 1,000-package limit ([#20398](astral-sh/uv#20398))
- Apply OSV fixed-version information only to the matching package and ecosystem ([#20399](astral-sh/uv#20399))
- Skip the virtualenv distutils monkeypatch on Python 3.10 and later ([#20222](astral-sh/uv#20222))
- Report invalid `uv audit --service-url` values instead of panicking ([#20374](astral-sh/uv#20374))
- Include preview settings in the published SchemaStore schema ([#20304](astral-sh/uv#20304))

### Performance

- Reduce resolver work by widening selected versions across ranges without other known candidates ([#20115](astral-sh/uv#20115))
- Defer client and build setup for no-op `uv sync` operations ([#20364](astral-sh/uv#20364))
- Reuse workspace discovery during frozen syncs ([#20363](astral-sh/uv#20363))
- Reuse workspace discovery after resolving settings ([#20356](http… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working preview Experimental behavior uv audit Related to uv audit functionality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants