refactor: replace poetry with uv - #123
Merged
Merged
Conversation
Michael Matzka (mima0815)
force-pushed
the
refactor/uv
branch
3 times, most recently
from
June 3, 2025 15:54
9c70fc0 to
65dc431
Compare
|
Fixed Issues (1)Great job! The following issues were fixed in this Pull Request
Communicate with Checkmarx by submitting a PR comment with Checkmarx (@Checkmarx) followed by one of the supported commands. Learn about the supported commands here. |
Michael Matzka (mima0815)
force-pushed
the
refactor/uv
branch
3 times, most recently
from
January 14, 2026 14:13
9d03cf0 to
1880b16
Compare
Michael Matzka (mima0815)
force-pushed
the
refactor/uv
branch
5 times, most recently
from
May 11, 2026 12:44
1bbb540 to
5e4fa01
Compare
Michael Matzka (mima0815)
force-pushed
the
refactor/uv
branch
from
September 7, 2026 08:58
5e4fa01 to
d3e6301
Compare
Michael Matzka (mima0815)
marked this pull request as ready for review
September 7, 2026 09:57
Michael Matzka (mima0815)
force-pushed
the
refactor/uv
branch
from
September 7, 2026 09:58
74cecdf to
fd65346
Compare
gdulafactset
approved these changes
Sep 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
Replaces Poetry with uv for dependency management, virtual envs, and packaging, and modernizes the surrounding tooling:
pyproject.tomlfrom[tool.poetry]to standard[project]metadata +[dependency-groups], and switched the build backend frompoetry-coreto uv's nativeuv_build(production-stable as of uv 0.11.19). Added[tool.uv.build-backend]withmodule-name = "fds.sdk.utils"andnamespace = trueso the backend correctly resolves thefds/fds.sdknamespace-package layout. Addeduv.lock, removedpoetry.lock.blackwithrufffor linting/formatting, and addedpyrightfor static type checking.tox/tox-gh-actions(tox.inideleted) — the version matrix is now run directly viauv run pytestper Python version in CI..github/workflows/ci.ymlandpublish.ymlto installuv(astral-sh/setup-uv) and useuv sync/uv build/uv publishinstead of Poetry; pinned third-party actions to commit SHAs. CI now also runsruff format --check,ruff check, andpyright, and the test matrix includes Python 3.14..github/workflows/codeql-analysis.yml— CodeQL scanning is superseded by the Checkmarx workflow added in chore(workflow): remove fortify scans in favor of checkmarx #159..python-version(3.10) and reformattedREADME.mdcode samples to matchruff formatoutput.While migrating, also fixed the issues surfaced by the new
ruff/pyrightchecks:ruff: implicit-Optionalparameter annotations inConfidentialClient.__init__, and mutable class-level default values (CONFIG_JWK_REQUIRED_KEYS, mockheadersdicts in tests) now useClassVar/| None.pyright: suppressed arequests_oauthlibstub limitation (verifytyped asbool | Nonethough a CA bundle path string is also valid) and aCONSTSsingleton typing conflict (removed the redundant class-to-instance reassignment). Also fixed two test bugs pyright caught:test_constructor_bad_paramswas passing theexample_configfixture function instead of its value, and the abstract-class instantiation checks intest_oauth2client.pynow have targetedpyright: ignoreannotations since they intentionally exercise aTypeErrorat runtime.No functional/runtime behavior changes to the package itself.
Links
Testing
uv run ruff check ./uv run ruff format --check— cleanuv run pyright— cleanuv run pytest— all 23 tests passuv build— verified wheel and sdist contain the samefds/sdk/utils/...layout as before (notests/included)ci.yml,publish.yml) updated and exercised via the PR checksChecklist
Ensure the following things have been met before requesting a review: