Fix NumPy 2.4+/Python 3.14 breakage, harden CI, adopt Renovate - #14
Merged
Merged
Conversation
Port two fixes from tuxu/python-samplerate: - 06e88d1 (tuxu#36): return a view instead of ndarray.resize(). On Python 3.14 with NumPy >= 2.4 resize() raises "cannot resize an array that may be referenced", breaking resample() and Resampler.process() on every call that trims output. 0.2.6 is affected. - 6d68220 (tuxu#34): pass Python_EXECUTABLE (what FindPython reads) instead of PYTHON_EXECUTABLE, so CMake builds against the interpreter running the build rather than the first one on PATH. The CallbackResampler.read port deliberately differs from upstream: upstream builds the mono 1-D view from the original buffer's pointer but the copied array as base, so the returned array points at freed memory. We take the pointer from the array we use as base. A regression test checks every truncated output shares memory with its base. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Pin every action to a commit SHA, default to `permissions: {}` and
grant `contents: read` per job, stop persisting checkout credentials.
zizmor (pedantic) goes from 14 findings to 0.
- Add a zizmor workflow that audits .github/ on change and weekly.
- Run push builds only for main and tags (PRs already run), plus a
weekly schedule so wheel tests pick up new NumPy releases between
releases; the NumPy 2.4 break went unnoticed for months.
- Build a wheel from the sdist and run the tests against it, so a file
missing from MANIFEST.in fails CI.
- Scheduled job testing against NumPy nightly on Python 3.14.
- cibuildwheel 3.3.0 -> 4.2.1; drop unused matrix keys and the
`submodules` option (there are none).
- Publish with pypa/gh-action-pypi-publish, which uploads PEP 740
attestations; fix the environment URL to the real PyPI project.
- Add renovate.json extending the LedFx org preset, with a regex
manager for the pybind11/libsamplerate FetchContent pins.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…novate MAINTAINING.md records how deps, vendored C/C++ and the upstream fork are kept current, which repo settings the automation relies on, and the last reviewed upstream commit. A Renovate git-refs manager bumps that marker when tuxu/python-samplerate moves, so upstream changes arrive as a PR. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Python 3.9 and 3.10 are end of life; stop building their wheels. The old `numpy>=1.7.0` floor was never installable on any supported Python. 1.23.2 is the first NumPy with CPython 3.11 wheels, and a new CI job runs the suite on Python 3.11 with exactly that version so the floor stays true. zizmor now runs on every PR so it can be a required check (a path-filtered required check never reports and blocks the PR). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PyPI showed only the upstream authors and no project links, so problems with these wheels could be reported to tuxu/python-samplerate. Add LedFx as author and point Homepage/Source/Issues here, with Upstream kept as its own link. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
0.2.6 is broken on Python 3.14 with NumPy ≥ 2.4. Every
resample()/Resampler.process()call that trims its output raisesValueError: cannot resize an array that may be referenced…. CI didn't notice because it only ran on push/PR and the lockfile pins NumPy 2.3.5.Changes
Upstream fixes ported from tuxu/python-samplerate:
06e88d1(Changes buffer resize to a view. tuxu/python-samplerate#36): return a view instead ofndarray.resize(). OurCallbackResampler.readport differs on purpose: upstream's mono 1-D short-read path returns an array pointing at freed memory. A new regression test fails on upstream's version and passes on ours.6d68220(Wheels bundle the wrong version tuxu/python-samplerate#34): passPython_EXECUTABLE, so wheels build against the right interpreter.96eb024,235d720,855b93b,40e7810.CI
permissions: {}by default, checkout credentials not persisted. zizmor findings: 14 → 0 (pedantic).zizmorworkflow on every PR and weekly.numpy_oldestjob: Python 3.11 + the NumPy floor read from pyproject.toml.pypa/gh-action-pypi-publish(PEP 740 attestations); fixed PyPI environment URL. Workflow filename andpypienvironment are unchanged, so trusted publishing still matches.Support matrix: CPython 3.11–3.14 (3.9/3.10 dropped, EOL);
numpy>=1.23.2(first with 3.11 wheels, was an uninstallable>=1.7.0).Package metadata: LedFx listed as author; Homepage/Source/Issues point at this repo (plus an Upstream link), so wheel problems get reported here rather than to tuxu.
Upkeep
renovate.jsonextends the new LedFx/renovate-config preset and adds regex managers for the pybind11/libsamplerate FetchContent pins and for a "last reviewed upstream commit" marker, so upstream changes arrive as a PR. Neither automerges. Both were dry-run with Renovate locally.MAINTAINING.md(upkeep plan, upstream sync, required repo settings) andSECURITY.md.Testing
After merge, tag v0.2.7 so LedFx on 3.14 works again.
🤖 Generated with Claude Code