Repository navigation
Honor direct sources shared across workspace dependencies - #20797
Merged
charliermarsh merged 11 commits intoJul 30, 2026
Conversation
charliermarsh
temporarily deployed
to
automations
July 29, 2026 18:38 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 18:55 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 19:05 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 19:16 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 19:35 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 19:43 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 20:35 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 21:01 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 21:48 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 29, 2026 22:07 — with
GitHub Actions
Inactive
charliermarsh
force-pushed
the
charlie/metadata-free-shared-direct-sources
branch
from
July 30, 2026 02:54
88db3c7 to
5b79b8a
Compare
charliermarsh
temporarily deployed
to
automations
July 30, 2026 02:55 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 30, 2026 14:53 — with
GitHub Actions
Inactive
charliermarsh
temporarily deployed
to
automations
July 30, 2026 15:18 — with
GitHub Actions
Inactive
charliermarsh
force-pushed
the
charlie/metadata-free-direct-url-constraint-fix
branch
from
July 30, 2026 21:14
8199039 to
49a7abe
Compare
charliermarsh
force-pushed
the
charlie/metadata-free-shared-direct-sources
branch
from
July 30, 2026 21:15
61b59a5 to
f2db47c
Compare
charliermarsh
temporarily deployed
to
automations
July 30, 2026 21:19 — with
GitHub Actions
Inactive
Base automatically changed from
charlie/metadata-free-direct-url-constraint-fix
to
main
July 30, 2026 22:01
charliermarsh
force-pushed
the
charlie/metadata-free-shared-direct-sources
branch
from
July 30, 2026 22:29
f2db47c to
b6cdd44
Compare
charliermarsh
changed the base branch from
main
to
charlie/metadata-free-conditional-source-authority
July 30, 2026 22:29
charliermarsh
temporarily deployed
to
automations
July 30, 2026 22:30 — with
GitHub Actions
Inactive
charliermarsh
merged commit Jul 30, 2026
b6cdd44
into
charlie/metadata-free-conditional-source-authority
charliermarsh
force-pushed
the
charlie/metadata-free-shared-direct-sources
branch
from
July 30, 2026 22:49
b6cdd44 to
17b4cba
Compare
Member
Author
|
(This was accidentally closed during some branch changes; it didn't merge into |
Member
Author
|
GitHub marked this pull request merged into the next feature branch while I was reordering the stack. The unchanged OpenAI-targeted diff now continues in #20847, based directly on |
charliermarsh
temporarily deployed
to
automations
July 30, 2026 22:51 — with
GitHub Actions
Inactive
charliermarsh
added a commit
that referenced
this pull request
Jul 31, 2026
## Summary When uv checks whether a metadata-free lockfile is still up to date, it reconstructs the dependencies that should appear in the lock. Previously, it looked at each package in isolation. That breaks when two packages share a dependency but only one specifies where it comes from. For example, package A might depend on `shared-package` from a local path, while package B simply depends on `shared-package`. The lock correctly resolves both dependencies to the local package, but validation treated package B's unqualified dependency as a registry dependency and rejected the lock. Offline, this meant a valid lock could be rejected even though nothing had changed. This change builds one shared view of direct-source requirements before validating the individual packages. The validator can then see that package A selected the exact source recorded in the lock when it checks package B. This also covers direct sources declared through extras, dependency groups, scripts, transitive local projects, and static or dynamic package metadata, while preserving the fast path for ordinary registry-only workspaces. Supersedes #20797, which GitHub marked merged while the stack was being reordered.
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Metadata-free lock freshness validation can reject a valid direct-source dependency when another dependency declares the same package without a source. Direct sources may be introduced by production requirements, optional extras, dependency groups, legacy development dependencies, projectless workspace-root groups, PEP 723 scripts, or non-workspace local source trees.
Index these direct requirements alongside constraints before reconstructing lockfile edges, including lowered
[tool.uv.sources]mappings, and accept an unqualified dependency only when an applicable declaration selects the exact locked source. Preserve the fast path for ordinary workspace members and cover workspace, optional/group, transitive local, projectless-root, and script sources with offline, uncached integration regressions.