pypi-upgrade-guard
Audit pinned Python dependencies against PyPI, pause for operator approval, apply upgrades with automatic rollback on smoke-test failure, and recover without re-auditing using examples/pypi_upgrade_guard/actions.py.
Warnings for the author
- "name" should match the name of the directory that holds SKILL.md
- Not listed through the skills extension: the directory must be named after the skill.
PyPI Upgrade Guard (pypi_upgrade_guard)
Executes the 3-stage dependency upgrade workflow with compensating rollback
using examples/pypi_upgrade_guard/actions.py.
Workflow Stages & Rules
-
Stage 1 — Audit Pinned Packages (
audit_pypi_versions):-
Call
actions.audit_pypi_versions(payload)with{"offline": True, "requirements_path": "<path>"}. -
Returns
(delta_dict, msg)wheredelta_dictcontains{"pinned": dict, "upgrades": list, "upgrade_count": int, "summary": str, "source": str}. -
Persist
delta_dictunderpayload["outputs"]["audit_pypi_versions"]soaudit_pypi_versionsis never re-executed in later steps. -
Example invocation:
python3 -B -c "import json, sys; sys.path.insert(0, 'examples/pypi_upgrade_guard'); import actions; d, m = actions.audit_pypi_versions({'offline': True}); print(json.dumps({'delta': d, 'message': m}))"
-
-
Stage 2 — Human Approval Gate (
approve_upgrades):- MANDATORY GATE: Stop after Stage 1 and present
delta_dict["summary"](upgrade_countpackages) to the human operator. - Wait for their explicit approval (
{"approved": True, "approved_by": "<user>", "smoke_test_cmd": "<cmd>"}). Never auto-approve.
- MANDATORY GATE: Stop after Stage 1 and present
-
Stage 3 — Apply Upgrades, Smoke-Test & Compensating Rollback (
apply_and_smoke_test):- Condition: Run only after Stage 2 is approved. Do not call
audit_pypi_versionsagain. - Construct
payloadwith"requirements_path","simulate_smoke_failure"(bool),"outputs": {"audit_pypi_versions": <delta_dict>, "approve_upgrades": {"approved": True}}. - Call
actions.apply_and_smoke_test(payload)inside atry / except Exception:block:- If
apply_and_smoke_test(payload)raises an exception, immediately callactions.restore_requirements_backup(payload)to restorerequirements_pathfromrequirements_path + ".bak"and remove.bak, then exit non-zero.
- If
- Failure Recovery: When recovering from a failed smoke test (e.g.,
with
"simulate_smoke_failure": False), re-run only Stage 3 using the savedoutputs.audit_pypi_versionsdict without re-running Stage 1.
- Condition: Run only after Stage 2 is approved. Do not call
Files of this skill
This skill has no supporting files.