Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
406 commits
Select commit Hold shift + click to select a range
710260f
Bump uv from 0.7.13 to 0.7.19 (#1827)
dependabot[bot] Jul 8, 2025
c8c1345
Bump uv from 0.7.19 to 0.7.20 (#1829)
dependabot[bot] Jul 10, 2025
d124912
Change the `python/` directory related warnings to errors (#1830)
edmorley Jul 10, 2025
3a0dde7
Prepare release v291 (#1831)
heroku-linguist[bot] Jul 10, 2025
608a912
Remove unused metrics (#1832)
edmorley Jul 15, 2025
cf11b63
Require a `Pipfile.lock` when using Pipenv (#1833)
edmorley Jul 15, 2025
c519e5a
Port uv test improvements to other package manager tests (#1834)
edmorley Jul 15, 2025
e8652f3
Update checks function names now that they error (#1836)
edmorley Jul 18, 2025
5cfd16c
Port package manager test improvements from CNB (#1835)
edmorley Jul 18, 2025
aac92f4
Bump the ruby-dependencies group with 2 updates (#1838)
dependabot[bot] Jul 22, 2025
e5206cb
Remove superseded `python_version_reason` metric (#1839)
edmorley Jul 23, 2025
f6bbc99
Update Pipenv to 2025.0.4 and improve installation/caching (#1840)
edmorley Jul 23, 2025
14f2d55
Prepare release v292 (#1841)
heroku-linguist[bot] Jul 23, 2025
0bb90f7
Work around Pipenv bug when using `--system` (#1842)
edmorley Jul 23, 2025
f6f2a29
Prepare release v293 (#1843)
heroku-linguist[bot] Jul 23, 2025
314c635
Add a build log message when the cache is being saved (#1844)
edmorley Jul 28, 2025
9494cc6
Speed up cache restoration (#1845)
edmorley Jul 28, 2025
e094206
Prepare release v294 (#1846)
heroku-linguist[bot] Jul 28, 2025
2997328
Bump uv from 0.7.20 to 0.8.4 (#1847)
dependabot[bot] Jul 31, 2025
0e85c3e
Bump rubocop from 1.78.0 to 1.79.1 in the ruby-dependencies group (#1…
dependabot[bot] Aug 1, 2025
593a05c
Improve tests for old Python versions (#1849)
edmorley Aug 1, 2025
26b8f86
Cleanup pip's `Requirement already satisfied` output on older Python …
edmorley Aug 1, 2025
a0b06f6
Prepare release v295 (#1852)
heroku-linguist[bot] Aug 1, 2025
4a11b01
Fix lint errors with Shellcheck v0.11.0 (#1853)
edmorley Aug 4, 2025
3e5f13b
Stop installing SQLite headers and CLI (#1854)
edmorley Aug 6, 2025
921b938
Bump rubocop from 1.79.1 to 1.79.2 in the ruby-dependencies group (#1…
dependabot[bot] Aug 6, 2025
22fc2cd
Prepare release v296 (#1856)
heroku-linguist[bot] Aug 6, 2025
d656472
Bump pip from 25.1.1 to 25.2 (#1848)
dependabot[bot] Aug 6, 2025
817b1e8
Bump poetry from 2.1.3 to 2.1.4 (#1858)
dependabot[bot] Aug 6, 2025
95cc4da
Bump uv from 0.8.4 to 0.8.5 (#1857)
dependabot[bot] Aug 6, 2025
ec807cc
Prepare release v297 (#1859)
heroku-linguist[bot] Aug 6, 2025
533db10
Fix the stack check error message for Heroku-20 (#1860)
edmorley Aug 6, 2025
1a7e472
Add support for Python 3.13.6 (#1861)
edmorley Aug 6, 2025
a6075a4
Prepare release v298 (#1862)
heroku-linguist[bot] Aug 6, 2025
edf0e01
Bump uv from 0.8.5 to 0.8.9 (#1866)
dependabot[bot] Aug 12, 2025
3cbdc93
Prepare release v299 (#1867)
heroku-linguist[bot] Aug 13, 2025
3e0b864
Add support for Python 3.13.7 (#1868)
edmorley Aug 15, 2025
51712df
Prepare release v300 (#1869)
heroku-linguist[bot] Aug 15, 2025
b0974da
Record cache restore duration for the empty cache case too (#1871)
edmorley Aug 18, 2025
e375ad3
Simplify handling of caches written by older buildpack versions (#1870)
edmorley Aug 18, 2025
c1f9208
Prepare release v301 (#1872)
heroku-linguist[bot] Aug 18, 2025
82379bd
Remove support for `BUILDPACK_S3_BASE_URL` (#1875)
edmorley Aug 19, 2025
fc152f6
Stop setting the `PYTHONHASHSEED` env var (#1876)
edmorley Aug 20, 2025
3c27de9
Add tests for build metadata contents (#1877)
edmorley Aug 20, 2025
db9788b
Refactor buildpack data store and `bin/report` (#1878)
edmorley Aug 21, 2025
5ffcadf
Prepare release v302 (#1879)
heroku-linguist[bot] Aug 21, 2025
5671ed7
Bump uv from 0.8.9 to 0.8.13 (#1880)
dependabot[bot] Aug 22, 2025
30086f2
Use EPOCHREALTIME in build_data timing logic (#1881)
dzuelke Aug 22, 2025
49e5bbc
Use contractions in user-facing messages (#1882)
edmorley Aug 25, 2025
577a619
Fix remaining shellcheck SC2250 instances (#1883)
edmorley Aug 26, 2025
f5893f4
Adjust curl timeouts, retries and logging (#1884)
edmorley Aug 26, 2025
1110174
Prepare release v303 (#1885)
heroku-linguist[bot] Aug 26, 2025
c2ba267
Improve Django collectstatic tests (#1887)
edmorley Aug 29, 2025
d0d55d0
Fix collectstatic and NLTK downloader for apps with `CACHE_DIR` set (…
edmorley Sep 1, 2025
8cbd877
Prepare release v304 (#1889)
heroku-linguist[bot] Sep 1, 2025
f557e8e
Output a warning if an existing virtual environment is found (#1890)
edmorley Sep 2, 2025
b525a25
Prepare release v305 (#1892)
heroku-linguist[bot] Sep 2, 2025
1172f9e
Delegate Ruby whitespace handling to RuboCop (#1893)
edmorley Sep 8, 2025
d60370b
Improve env var and package manager tests (#1895)
edmorley Sep 9, 2025
3f9caa0
Bump uv from 0.8.13 to 0.8.15 (#1894)
dependabot[bot] Sep 9, 2025
5dcc5c4
Prepare release v306 (#1896)
heroku-linguist[bot] Sep 9, 2025
487f511
Deprecate implicit setup.py support (#1897)
edmorley Sep 10, 2025
719eb30
Prepare release v307 (#1898)
heroku-linguist[bot] Sep 10, 2025
b866992
Bump uv from 0.8.15 to 0.8.17 (#1899)
dependabot[bot] Sep 17, 2025
189463c
Bump poetry from 2.1.4 to 2.2.0 (#1900)
dependabot[bot] Sep 17, 2025
04d8c0d
Bump uv from 0.8.17 to 0.8.18 (#1901)
dependabot[bot] Sep 18, 2025
4253490
Speed up cache saving (#1902)
edmorley Sep 18, 2025
2e852f4
Prepare release v308 (#1903)
heroku-linguist[bot] Sep 19, 2025
d99a337
Add metrics for misspelled `.python-version` files (#1904)
edmorley Sep 19, 2025
4d20ad3
Prepare release v309 (#1905)
heroku-linguist[bot] Sep 19, 2025
2debd95
Improve metrics for failed uv archive downloads (#1908)
edmorley Sep 22, 2025
62f4973
Use `cp --no-dereference` when saving the cache (#1909)
edmorley Sep 23, 2025
337ffbc
Bump uv from 0.8.18 to 0.8.20 (#1910)
dependabot[bot] Sep 23, 2025
42910fb
Bump poetry from 2.2.0 to 2.2.1 (#1907)
dependabot[bot] Sep 23, 2025
732efcb
Prepare release v310 (#1911)
heroku-linguist[bot] Sep 23, 2025
b2c9f8c
Remove unnecessary tar `--no-anchored` (#1912)
edmorley Sep 29, 2025
a3caefb
Use a consistent prefix for checks `failure_reason`s (#1913)
edmorley Sep 29, 2025
136c3a1
Further expand buildpack detection known file list (#1914)
edmorley Sep 29, 2025
0576746
Use `pip install --isolated` when bootstrapping pip/Pipenv/Poetry (#1…
edmorley Sep 29, 2025
40c6272
Always use `|&` with `output::indent` (#1917)
edmorley Sep 30, 2025
6dbce78
Stop rewriting Django collectstatic command log output (#1918)
edmorley Sep 30, 2025
4370ee7
Prepare release v311 (#1919)
heroku-linguist[bot] Sep 30, 2025
8888cd4
Bump actions/checkout from 4 to 5 (#1921)
dependabot[bot] Oct 1, 2025
62ac1f9
Bump the ruby-dependencies group with 2 updates (#1920)
dependabot[bot] Oct 1, 2025
540b3c9
Bump uv from 0.8.20 to 0.8.22 (#1916)
dependabot[bot] Oct 3, 2025
eee1572
Bump uv from 0.8.22 to 0.8.23 (#1922)
dependabot[bot] Oct 5, 2025
a361dfa
Prepare release v312 (#1923)
heroku-linguist[bot] Oct 5, 2025
5f8ddb6
Switch from GPG to Sigstore for Python source verification (#1924)
edmorley Oct 6, 2025
227fcbf
Stop compiling Python using `--with-system-expat` (#1925)
edmorley Oct 6, 2025
b494ced
Add support for Python 3.14 (#1927)
edmorley Oct 9, 2025
aed5485
Add support for Python 3.13.8 (#1928)
edmorley Oct 9, 2025
5583aff
Add support for Python 3.12.12, 3.11.14, 3.10.19, 3.9.24 (#1929)
edmorley Oct 9, 2025
72690d3
Prepare release v313 (#1930)
heroku-linguist[bot] Oct 9, 2025
fc63f31
Use a consistent `failure_reason` prefix for all internal errors (#1932)
edmorley Oct 14, 2025
258dfa0
Improve error messages and metrics for unhandled errors (#1933)
edmorley Oct 14, 2025
5ac2b10
Add support for Python 3.13.9 (#1934)
edmorley Oct 15, 2025
874e468
Prepare release v314 (#1935)
heroku-linguist[bot] Oct 15, 2025
2fe232c
Update Dependabot config for Docker (#1936)
edmorley Oct 15, 2025
99b8ba6
Remove redundant internal error handling for venv creation (#1937)
edmorley Oct 15, 2025
0ef4ac2
Bump sigstore/cosign/cosign from v2.6.1 to v3.0.2 in /builds (#1938)
dependabot[bot] Oct 15, 2025
1f0c3c9
Stop using a global warnings log file (#1939)
edmorley Oct 16, 2025
38f7d1f
Clean up the install pip step (#1940)
edmorley Oct 16, 2025
58f10eb
Pin Poetry's `dulwich` version (#1943)
edmorley Oct 21, 2025
088bce0
Bump the ruby-dependencies group across 1 directory with 2 updates (#…
dependabot[bot] Oct 21, 2025
9311dd8
Bump uv from 0.8.23 to 0.9.4 (#1942)
dependabot[bot] Oct 21, 2025
b77cfee
Bump uv from 0.9.4 to 0.9.5 in /requirements (#1945)
dependabot[bot] Oct 21, 2025
a8b7f3d
Prepare release v315 (#1946)
heroku-linguist[bot] Oct 22, 2025
3b25a5b
Improve Python version error message for invisible Unicode whitespace…
edmorley Oct 24, 2025
d134601
Record the file encoding of `.python-version` and `runtime.txt` (#1948)
edmorley Oct 27, 2025
850c60d
Prepare release v316 (#1949)
heroku-linguist[bot] Oct 27, 2025
dfe88af
Bump uv from 0.9.5 to 0.9.7 (#1952)
dependabot[bot] Oct 31, 2025
070b7da
Pin GDAL version in tests (#1954)
edmorley Nov 3, 2025
ef05ca9
Bump rubocop from 1.81.6 to 1.81.7 in the ruby-dependencies group (#1…
dependabot[bot] Nov 3, 2025
b2f3bdf
Add support for Python 3.9.25 (#1955)
edmorley Nov 3, 2025
5cdf8f2
Prepare release v317 (#1956)
heroku-linguist[bot] Nov 3, 2025
cde4b67
Improve `.python-version` and `runtime.txt` error handling (#1958)
edmorley Nov 12, 2025
947eb15
Prepare release v318 (#1959)
heroku-linguist[bot] Nov 12, 2025
2f603c8
Bump uv from 0.9.7 to 0.9.9 (#1961)
dependabot[bot] Nov 13, 2025
9ca9559
Always use `local` for vars inside functions (#1960)
edmorley Nov 13, 2025
94209ab
Further improve `.python-version` and `runtime.txt` error handling (#…
edmorley Nov 14, 2025
b732e6f
Improve the error message when the build data file has been deleted (…
edmorley Nov 14, 2025
9962336
Work around tmpfs default permissions regression in runc 1.3.3 (#1964)
edmorley Nov 14, 2025
1e30096
Prepare release v319 (#1965)
heroku-linguist[bot] Nov 14, 2025
d9c73e2
Fixed regex for null bytes character replacement (#1966)
edmorley Nov 17, 2025
b4260ad
Unpin Poetry's `dulwich` version (#1967)
edmorley Nov 17, 2025
2bf1d7d
Add a check for misspelled `.python-version` files (#1970)
edmorley Nov 20, 2025
7131c23
Refactor Bash output helpers (#1968)
schneems Nov 20, 2025
89efadc
Prepare release v320 (#1971)
heroku-linguist[bot] Nov 20, 2025
38c81f8
Deprecate support for Python 3.10 (#1972)
edmorley Nov 21, 2025
03cc02e
Bump uv from 0.9.9 to 0.9.11 (#1973)
dependabot[bot] Nov 21, 2025
d668dbe
Change the way pip version checks are disabled (#1974)
edmorley Nov 21, 2025
d8a984d
Add more messaging to the build log recommending uv (#1975)
edmorley Nov 21, 2025
5fec34c
Prepare release v321 (#1976)
heroku-linguist[bot] Nov 21, 2025
1baf44d
Bump actions/checkout from 5 to 6 (#1978)
dependabot[bot] Dec 2, 2025
2a761ab
Bump rubocop-rspec from 3.7.0 to 3.8.0 in the ruby-dependencies group…
dependabot[bot] Dec 2, 2025
777d498
Use buildpack banner from `heroku/buildpacks` (#1981)
runesoerensen Dec 2, 2025
cd9e505
Bump uv from 0.9.11 to 0.9.14 (#1979)
dependabot[bot] Dec 2, 2025
e6b2065
Add support for Python 3.14.1 and 3.13.10 (#1982)
edmorley Dec 2, 2025
209c77b
Prepare release v322 (#1983)
heroku-linguist[bot] Dec 2, 2025
2b1f8a0
Use Python 3.14 as the default Python version for new apps (#1984)
edmorley Dec 4, 2025
65a57e9
Add support for Python 3.14.2 and 3.13.11 (#1985)
edmorley Dec 5, 2025
40e6dfa
Prepare release v323 (#1986)
heroku-linguist[bot] Dec 5, 2025
f3b29ee
Stop adding the current working directory to `PATH` (#1987)
edmorley Dec 8, 2025
8997ea7
Convert the existing virtual environment warning to an error (#1990)
edmorley Dec 8, 2025
b9c2dc0
Prepare release v324 (#1991)
heroku-linguist[bot] Dec 9, 2025
6d06c3b
Sunset implicit setup.py support (#1992)
edmorley Dec 9, 2025
b66b202
Error when multiple package manager files are found (#1993)
edmorley Dec 10, 2025
e6ebda9
Bump uv from 0.9.14 to 0.9.17 (#1995)
dependabot[bot] Dec 10, 2025
2f3fb4f
Prepare release v325 (#1996)
heroku-linguist[bot] Dec 10, 2025
a3bfa42
Unpin GDAL version in tests (#1998)
edmorley Dec 16, 2025
689ddf5
Bump sigstore/cosign/cosign from v3.0.2 to v3.0.3 in /builds (#2002)
dependabot[bot] Jan 4, 2026
ed233c7
Bump rubocop from 1.81.7 to 1.82.1 in the ruby-dependencies group (#2…
dependabot[bot] Jan 4, 2026
4ee96db
Bump uv from 0.9.17 to 0.9.21 (#2003)
dependabot[bot] Jan 5, 2026
2833d03
Prepare release v326 (#2004)
heroku-linguist[bot] Jan 5, 2026
2161b9b
Adjust the error message shown for missing SQLite headers (#2006)
edmorley Jan 7, 2026
24eee50
Remove Python 3.9 support (#2005)
edmorley Jan 7, 2026
76f07d9
Prepare release v327 (#2007)
heroku-linguist[bot] Jan 7, 2026
66de50f
Update pip from 25.2 to 25.3 (#2008)
edmorley Jan 7, 2026
6a5c28d
Prepare release v328 (#2009)
heroku-linguist[bot] Jan 7, 2026
38713f3
Bump pipenv from 2025.0.4 to 2026.0.3 (#2000)
dependabot[bot] Jan 8, 2026
f2c6773
Prepare release v329 (#2010)
heroku-linguist[bot] Jan 8, 2026
1b26c62
Re-apply Pipenv `--system` bug workaround (#2011)
edmorley Jan 8, 2026
f02fbdb
Prepare release v330 (#2012)
heroku-linguist[bot] Jan 8, 2026
4761063
Bump uv from 0.9.21 to 0.9.24 (#2013)
dependabot[bot] Jan 11, 2026
4878b11
Prepare release v331 (#2014)
heroku-linguist[bot] Jan 11, 2026
4e00e12
Set `WEB_CONCURRENCY_SET_BY` if appropriate (#2015)
edmorley Jan 13, 2026
3bddce4
Bump rubocop-rspec from 3.8.0 to 3.9.0 in the ruby-dependencies group…
dependabot[bot] Jan 26, 2026
e830581
Bump sigstore/cosign/cosign from v3.0.3 to v3.0.4 in /builds (#2020)
dependabot[bot] Jan 26, 2026
4011224
Bump poetry from 2.2.1 to 2.3.1 (#2019)
dependabot[bot] Jan 26, 2026
4f9718c
Bump uv from 0.9.24 to 0.9.26 (#2016)
dependabot[bot] Jan 26, 2026
f9ce6a6
Prepare release v332 (#2021)
heroku-linguist[bot] Jan 26, 2026
ab4d77d
Bump rubocop from 1.82.1 to 1.84.0 in the ruby-dependencies group (#2…
dependabot[bot] Feb 2, 2026
827b129
Add support for Python 3.14.3 and 3.13.12 (#2027)
edmorley Feb 4, 2026
c43df60
Prepare release v333 (#2028)
heroku-linguist[bot] Feb 4, 2026
0c7b05c
Bump poetry from 2.3.1 to 2.3.2 (#2024)
dependabot[bot] Feb 4, 2026
9d0be84
Bump uv from 0.9.26 to 0.9.29 (#2029)
dependabot[bot] Feb 4, 2026
53b747d
Prepare release v334 (#2030)
heroku-linguist[bot] Feb 4, 2026
2d975f8
Bump uv from 0.9.29 to 0.10.1 (#2031)
dependabot[bot] Feb 10, 2026
8eaa83c
Prepare release v335 (#2033)
heroku-linguist[bot] Feb 10, 2026
96e5bea
Switch to AWS' dual-stack S3 URLs (#2035)
edmorley Feb 23, 2026
361215e
Work around NLTK v3.9.3 regression (#2042)
edmorley Mar 2, 2026
3af8b10
Bump rubocop from 1.84.0 to 1.85.0 in the ruby-dependencies group (#2…
dependabot[bot] Mar 2, 2026
d06b98c
Bump sigstore/cosign/cosign from v3.0.4 to v3.0.5 in /builds (#2040)
dependabot[bot] Mar 2, 2026
a6e6ac0
Prepare release v336 (#2038)
heroku-linguist[bot] Mar 2, 2026
522aeb0
Bump pip from 25.3 to 26.0.1 (#2032)
dependabot[bot] Mar 2, 2026
3b5d531
Update to Ruby 4.0 (#2043)
edmorley Mar 3, 2026
a64b2d9
Explicitly configure uv to use hard links (#2044)
edmorley Mar 3, 2026
26565e4
Bump uv from 0.10.1 to 0.10.7 (#2041)
dependabot[bot] Mar 3, 2026
ab4ed89
Prepare release v337 (#2045)
heroku-linguist[bot] Mar 3, 2026
07bf8f0
Add support for Python 3.12.13, 3.11.15 and 3.10.20 (#2046)
edmorley Mar 3, 2026
855d7e6
Prepare release v338 (#2047)
heroku-linguist[bot] Mar 3, 2026
4f3aa88
Update test fixture after change in S3 bucket permissions (#2048)
edmorley Mar 4, 2026
75dd5af
Bump uv from 0.10.7 to 0.10.9 (#2049)
dependabot[bot] Mar 12, 2026
108a416
Download uv from `releases.astral.sh` instead of GitHub releases (#2050)
edmorley Mar 12, 2026
9a9cb66
Add more misspellings to the `.python-version` filename check (#2051)
edmorley Mar 13, 2026
76fa6db
Prepare release v339 (#2052)
heroku-linguist[bot] Mar 13, 2026
3303da8
Bump json from 2.18.1 to 2.19.2 (#2055)
dependabot[bot] Mar 19, 2026
8b3b0e8
Add binary build support for Heroku-26 (#2056)
edmorley Mar 20, 2026
f6f11c0
Fix GUSINFO metadata in CODEOWNERS (#2059)
edmorley Mar 23, 2026
e8b7c62
Bump rubocop from 1.85.0 to 1.86.0 in the ruby-dependencies group (#2…
dependabot[bot] Mar 27, 2026
3310064
Bump uv from 0.10.9 to 0.11.3 (#2067)
dependabot[bot] Apr 2, 2026
c5545e9
Bump poetry from 2.3.2 to 2.3.3 (#2064)
dependabot[bot] Apr 2, 2026
d02e0cb
Bump pipenv from 2026.0.3 to 2026.5.1 (#2065)
dependabot[bot] Apr 2, 2026
20fd633
Prepare release v340 (#2068)
heroku-linguist[bot] Apr 2, 2026
843f76f
Reduce Dependabot frequency for Python dependencies (#2069)
edmorley Apr 2, 2026
845b74a
Fix typos and other inconsistencies in comments, tests and CHANGELOG …
edmorley Apr 7, 2026
255d0a8
Add support for Python 3.14.4 and 3.13.13 (#2071)
edmorley Apr 7, 2026
240f6b8
Prepare release v341 (#2072)
heroku-linguist[bot] Apr 7, 2026
ffd66f3
Add buildpack support for Heroku-26 (#2073)
edmorley Apr 9, 2026
b609ad5
Prepare release v342 (#2074)
heroku-linguist[bot] Apr 9, 2026
62fb854
Fix outdated NLTK `sub_env` comment (#2075)
edmorley Apr 10, 2026
ab1d03f
Stop using global variable in `warn_or_error_if_python_version_file_m…
edmorley Apr 10, 2026
8123714
Fix `build_data::get_previous()` discarding stored `false` values (#2…
edmorley Apr 10, 2026
065e162
Bump uv from 0.11.3 to 0.11.6 in /requirements (#2078)
dependabot[bot] Apr 13, 2026
7990ed7
Bump poetry from 2.3.3 to 2.3.4 (#2079)
dependabot[bot] Apr 13, 2026
36b45f7
Bump pipenv from 2026.5.1 to 2026.5.2 (#2080)
dependabot[bot] Apr 13, 2026
b821610
Prepare release v343 (#2081)
heroku-linguist[bot] Apr 13, 2026
88cd62e
Update Pipenv editable test assertion (#2087)
edmorley May 7, 2026
14acb96
Bump sigstore/cosign/cosign from v3.0.5 to v3.0.6 in /builds (#2086)
dependabot[bot] May 7, 2026
ed0226a
Bump rubocop in the ruby-dependencies group across 1 directory (#2083)
dependabot[bot] May 7, 2026
0152f96
Bump uv from 0.11.6 to 0.11.11 (#2090)
dependabot[bot] May 7, 2026
233b55c
Bump pip from 26.0.1 to 26.1.1 (#2089)
dependabot[bot] May 7, 2026
7eb4d6b
Bump poetry from 2.3.4 to 2.4.0 (#2088)
dependabot[bot] May 7, 2026
4fa8d49
Bump pipenv from 2026.5.2 to 2026.6.1 (#2082)
dependabot[bot] May 7, 2026
27b1abb
Group Python Dependabot PRs too (#2091)
edmorley May 7, 2026
bb2c673
Fix Dependabot config file syntax (#2092)
edmorley May 7, 2026
b123a44
Prepare release v344 (#2093)
heroku-linguist[bot] May 7, 2026
058ba27
Add support for Python 3.14.5 (#2094)
edmorley May 11, 2026
1bdfe9b
Prepare release v345 (#2095)
heroku-linguist[bot] May 11, 2026
d18722b
Bump rubocop from 1.86.1 to 1.87.0 in the ruby-dependencies group (#2…
dependabot[bot] Jun 4, 2026
6d2b511
Bump the python-dependencies group across 1 directory with 3 updates …
dependabot[bot] Jun 4, 2026
871f8a1
Prepare release v345 (#2100)
heroku-linguist[bot] Jun 4, 2026
18826fe
Fix CHANGELOG for release that didn't occur (#2101)
edmorley Jun 5, 2026
689b417
Add OIDC-based buildpack release workflow (#2099)
colincasey Jun 8, 2026
ccc4d5e
Fix intermittent `profile.d/` scripts test failure from extra trailin…
edmorley Jun 8, 2026
fadb85e
Bump rubocop-rspec from 3.9.0 to 3.10.2 in the ruby-dependencies grou…
dependabot[bot] Jun 9, 2026
c332164
Add support for Python 3.14.6 and 3.13.14 (#2105)
edmorley Jun 10, 2026
e0a66e5
Prepare release v346 (#2106)
heroku-linguist[bot] Jun 10, 2026
7db11ed
Configure classic publish notifications (#2107)
colincasey Jun 16, 2026
32bf66e
Fix inaccurate `PYTHONUNBUFFERED` comment (#2108)
edmorley Jun 16, 2026
8095af0
Route builds/Dockerfile Dependabot bumps to maintainer in CODEOWNERS …
edmorley Jul 3, 2026
6d3b487
Bump sigstore/cosign/cosign from v3.0.6 to v3.1.1 in /builds (#2112)
dependabot[bot] Jul 3, 2026
814c457
Bump actions/checkout from 6 to 7 (#2109)
dependabot[bot] Jul 3, 2026
115dcc8
Bump rubocop from 1.87.0 to 1.88.1 in the ruby-dependencies group (#2…
dependabot[bot] Jul 3, 2026
072ebb9
Post Honeycomb release marker on release (#2114)
colincasey Jul 6, 2026
8ef81fc
Fix intermittent one-off dyno test failures from extra trailing newli…
edmorley Jul 8, 2026
b38040b
Bump the python-dependencies group across 1 directory with 2 updates …
dependabot[bot] Jul 10, 2026
e83797a
Prepare release v347 (#2116)
heroku-linguist[bot] Jul 10, 2026
f4f329e
Add CODE_OF_CONDUCT.md and SECURITY.md (#2117)
edmorley Jul 14, 2026
e3b3a4d
Hardcode the setuptools version instead of using Dependabot (#2119)
edmorley Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
37 changes: 37 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# https://editorconfig.org
root = true

[*]
charset = utf-8
end_of_line = lf
indent_style = space
insert_final_newline = true
trim_trailing_whitespace = true

[*.rb]
# Required since we use heredocs to assert against Hatchet output, and sometimes that output
# contains trailing newlines. Our RuboCop config ensures these are only allowed in heredocs.
trim_trailing_whitespace = false

[*.sh]
binary_next_line = true
# We sadly have to use tabs in shell scripts otherwise we can't indent here documents:
# https://www.gnu.org/software/bash/manual/html_node/Redirections.html#Here-Documents
indent_style = tab
shell_variant = bash
switch_case_indent = true

# Catches scripts that we can't give a .sh file extension, such as the Buildpack API scripts.
[**/bin/**]
binary_next_line = true
indent_style = tab
shell_variant = bash
switch_case_indent = true

# The setup-ruby GitHub Action creates this directory when caching is enabled, and if
# it's not ignored will cause false positives when running shfmt in the CI lint job.
[vendor/bundle/**]
ignore = true

[Makefile]
indent_style = tab
4 changes: 4 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,8 +1,12 @@
# Default to requesting pull request reviews from the Heroku Languages team.
#ECCN:Open Source
#GUSINFO:Heroku - Languages,Heroku Python Platform
* @heroku/languages

# However, request review from the language owner instead for files that are updated
# by Dependabot or release automation, to reduce team review request noise.
CHANGELOG.md @edmorley
Gemfile.lock @edmorley
/.github/workflows/ @edmorley
/builds/Dockerfile @edmorley
/requirements/ @edmorley
14 changes: 14 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,14 @@ updates:
update-types:
- "minor"
- "patch"
- package-ecosystem: "docker"
directory: "/builds"
schedule:
interval: "monthly"
labels:
- "dependencies"
- "docker"
- "skip changelog"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
Expand All @@ -28,3 +36,9 @@ updates:
labels:
- "dependencies"
- "python"
groups:
# We don't limit grouping for Python to just minor/patch versions, since pip doesn't follow
# semver, plus having to update CHANGELOG.md means it's easier to just have a single PR.
python-dependencies:
patterns:
- "*"
40 changes: 21 additions & 19 deletions .github/workflows/build_python_runtime.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,17 +5,17 @@ on:
workflow_dispatch:
inputs:
python_version:
description: "Python version (eg: 3.12.0)"
description: "Python version (eg: 3.13.0)"
type: string
required: true
stack:
description: "Stack(s)"
type: choice
options:
- auto
- heroku-20
- heroku-22
- heroku-24
- heroku-26
default: auto
required: false
dry_run:
Expand All @@ -36,14 +36,14 @@ env:
# Unfortunately these jobs cannot be easily written as a matrix since `matrix.exclude` does not
# support expression syntax, and the `matrix` context is not available inside the job `if` key.
jobs:
heroku-20:
if: inputs.stack == 'heroku-20' || inputs.stack == 'auto'
heroku-22:
if: inputs.stack == 'heroku-22' || inputs.stack == 'auto'
runs-on: pub-hk-ubuntu-24.04-xlarge
env:
STACK_VERSION: "20"
STACK_VERSION: "22"
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Build Docker image
run: docker build --platform="linux/amd64" --pull --tag buildenv --build-arg=STACK_VERSION builds/
- name: Compile and package Python runtime
Expand All @@ -57,41 +57,43 @@ jobs:
if: (!inputs.dry_run)
run: aws s3 sync ./upload "s3://${S3_BUCKET}"

heroku-22:
# On Heroku-22 we only support Python 3.9+.
if: inputs.stack == 'heroku-22' || (inputs.stack == 'auto' && !startsWith(inputs.python_version,'3.8.'))
runs-on: pub-hk-ubuntu-24.04-xlarge
heroku-24:
if: inputs.stack == 'heroku-24' || inputs.stack == 'auto'
strategy:
fail-fast: false
matrix:
arch: ["amd64", "arm64"]
runs-on: ${{ matrix.arch == 'arm64' && 'pub-hk-ubuntu-24.04-arm-xlarge' || 'pub-hk-ubuntu-24.04-xlarge' }}
env:
STACK_VERSION: "22"
STACK_VERSION: "24"
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Build Docker image
run: docker build --platform="linux/amd64" --pull --tag buildenv --build-arg=STACK_VERSION builds/
run: docker build --platform="linux/${{ matrix.arch }}" --pull --tag buildenv --build-arg=STACK_VERSION builds/
- name: Compile and package Python runtime
run: docker run --rm --volume="${PWD}/upload:/tmp/upload" buildenv ./build_python_runtime.sh "${{ inputs.python_version }}"
- name: Test Python runtime
run: |
RUN_IMAGE='heroku/heroku:${{ env.STACK_VERSION }}'
ARCHIVE_FILENAME='python-${{ inputs.python_version }}-ubuntu-${{ env.STACK_VERSION }}.04-amd64.tar.zst'
ARCHIVE_FILENAME='python-${{ inputs.python_version }}-ubuntu-${{ env.STACK_VERSION }}.04-${{ matrix.arch }}.tar.zst'
docker run --rm --volume="${PWD}/upload:/upload:ro" --volume="${PWD}/builds:/builds:ro" "${RUN_IMAGE}" /builds/test_python_runtime.sh "/upload/${ARCHIVE_FILENAME}"
- name: Upload Python runtime archive to S3
if: (!inputs.dry_run)
run: aws s3 sync ./upload "s3://${S3_BUCKET}"

heroku-24:
# On Heroku-24 we only support Python 3.10+.
if: inputs.stack == 'heroku-24' || (inputs.stack == 'auto' && !startsWith(inputs.python_version,'3.8.') && !startsWith(inputs.python_version,'3.9.'))
heroku-26:
if: inputs.stack == 'heroku-26' || inputs.stack == 'auto'
strategy:
fail-fast: false
matrix:
arch: ["amd64", "arm64"]
runs-on: ${{ matrix.arch == 'arm64' && 'pub-hk-ubuntu-24.04-arm-xlarge' || 'pub-hk-ubuntu-24.04-xlarge' }}
env:
STACK_VERSION: "24"
STACK_VERSION: "26"
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Build Docker image
run: docker build --platform="linux/${{ matrix.arch }}" --pull --tag buildenv --build-arg=STACK_VERSION builds/
- name: Compile and package Python runtime
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/check_changelog.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
if: (!contains(github.event.pull_request.labels.*.name, 'skip changelog'))
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Check that CHANGELOG is touched
run: |
git fetch origin ${{ github.base_ref }} --depth 1 && \
Expand Down
33 changes: 18 additions & 15 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,19 +10,27 @@ on:
permissions:
contents: read

env:
# Used by shfmt and more.
FORCE_COLOR: 1

jobs:
lint:
runs-on: ubuntu-24.04
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install Ruby and dependencies
uses: ruby/setup-ruby@v1
with:
bundler-cache: true
ruby-version: "3.3"
ruby-version: "4.0"
- name: Run ShellCheck
run: make lint-scripts
- name: Run shfmt
uses: docker://mvdan/shfmt:latest
with:
args: "--diff ."
- name: Run Rubocop
run: bundle exec rubocop

Expand All @@ -31,24 +39,24 @@ jobs:
strategy:
fail-fast: false
matrix:
stack: ["heroku-20", "heroku-22", "heroku-24"]
stack: ["heroku-22", "heroku-24", "heroku-26"]
env:
HATCHET_APP_LIMIT: 200
HATCHET_APP_LIMIT: 300
HATCHET_DEFAULT_STACK: ${{ matrix.stack }}
HATCHET_EXPENSIVE_MODE: 1
HEROKU_API_KEY: ${{ secrets.HEROKU_API_KEY }}
HEROKU_API_USER: ${{ secrets.HEROKU_API_USER }}
HEROKU_DISABLE_AUTOUPDATE: 1
PARALLEL_SPLIT_TEST_PROCESSES: 60
RSPEC_RETRY_RETRY_COUNT: 3
PARALLEL_SPLIT_TEST_PROCESSES: 90
RSPEC_RETRY_RETRY_COUNT: 1
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install Ruby and dependencies
uses: ruby/setup-ruby@v1
with:
bundler-cache: true
ruby-version: "3.3"
ruby-version: "4.0"
- name: Hatchet setup
run: bundle exec hatchet ci:setup
- name: Run Hatchet integration tests
Expand All @@ -57,17 +65,12 @@ jobs:

container-test:
runs-on: ubuntu-24.04
defaults:
run:
# Work around lack of TTY causing errors when using `docker run -it`:
# https://github.com/actions/runner/issues/241
shell: 'script -q -e -c "bash -eo pipefail {0}"'
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
# These test both the local development `make run` workflow and that `bin/report` completes successfully
# for both passing and failing builds (since `bin/report` can't easily be tested via Hatchet tests).
- name: Run buildpack using default app fixture
run: make run
- name: Run buildpack using an app fixture that's expected to fail
run: make run FIXTURE=spec/fixtures/python_version_invalid/
run: make run FIXTURE=spec/fixtures/python_version_file_invalid_version/ COMPILE_FAILURE_EXIT_CODE=0
4 changes: 2 additions & 2 deletions .github/workflows/hatchet_app_cleaner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,12 @@ jobs:
HEROKU_DISABLE_AUTOUPDATE: 1
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install Ruby and dependencies
uses: ruby/setup-ruby@v1
with:
bundler-cache: true
ruby-version: "3.3"
ruby-version: "4.0"
- name: Run Hatchet destroy
# Only apps older than 10 minutes are destroyed, to ensure that any
# in progress CI runs are not interrupted.
Expand Down
36 changes: 36 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: Release Buildpack

on:
# Auto-trigger when the "Prepare release" PR (created by the
# _classic-buildpack-prepare-release.yml workflow) is merged.
pull_request:
branches:
- main
types:
- closed
workflow_dispatch:

permissions:
id-token: write
contents: write

jobs:
release:
name: Release
# On `pull_request`, only run for the merged auto-generated
# "Prepare release" PR (branch name set by
# _classic-buildpack-prepare-release.yml). Manual dispatches always run.
if: >-
github.event_name == 'workflow_dispatch' ||
(github.event.pull_request.merged == true &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.head.ref == 'prepare-release' &&
github.event.pull_request.user.login == 'heroku-linguist[bot]')
uses: heroku/languages-github-actions/.github/workflows/_classic-buildpack-publish.yml@latest
with:
buildpack_id: "heroku/python"
app_id: ${{ vars.LINGUIST_GH_APP_ID }}
secrets:
app_private_key: ${{ secrets.LINGUIST_GH_PRIVATE_KEY }}
slack_webhook_url: ${{ secrets.BUILDPACK_RELEASE_FAILURE_WEBHOOK_URL }}
honeycomb_api_key: ${{ secrets.HONEYCOMB_API_KEY }}
1 change: 0 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
__pycache__/
.hatchet/repos/
.venv/
# The setup-ruby GitHub Action creates this directory when caching is enabled, so we ignore
# it here so it does not show up in the output of `git ls-files` for `make lint-scripts`.
Expand Down
2 changes: 1 addition & 1 deletion .rubocop.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
require:
plugins:
- rubocop-rspec

AllCops:
Expand Down
13 changes: 0 additions & 13 deletions .shellcheckrc
Original file line number Diff line number Diff line change
@@ -1,15 +1,2 @@
# Enable all checks, including the optional ones that are off by default.
enable=all

# TODO: Triage and potentially enable more of these optional checks.

# SC2154 (warning): var is referenced but not assigned.
disable=SC2154
# SC2250 (style): Prefer putting braces around variable references even when not strictly required.
disable=SC2250
# SC2310 (info): This function is invoked in an 'if' condition so set -e will be disabled.
disable=SC2310
# SC2311 (info): Bash implicitly disabled set -e for this function invocation because it's inside a command substitution.
disable=SC2311
# SC2312 (info): Consider invoking this command separately to avoid masking its return value
disable=SC2312
Loading