From 84e7dba52e4b3072c1114fe6348bc9c0a77e65cc Mon Sep 17 00:00:00 2001 From: Manuel Raynaud Date: Tue, 20 Jan 2026 18:53:06 +0100 Subject: [PATCH] =?UTF-8?q?=E2=99=BB=EF=B8=8F(backend)=20migrate=20from=20?= =?UTF-8?q?setuptool=20to=20uv=5Fbuild=20as=20build=20backend?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Recently a CVE present in a dependency of setuptool is blocking our CI. The CVE is fixed, a new release of the dependency (jaraco.context) is made but the setuptool project is not updating it. We already migrate from pip to uv to manage our dependencies. We can also migrate the build backend from setuptool to uv_build. In the pyproject file, the readme property has been removed, because uv_build try to read it, but the readme is at the root of the project and not copied into the Dockerfile instructions. This readme can be used when the package is published on pypi but it is not the case for Drive. --- .github/workflows/crowdin_upload.yml | 4 ++-- Dockerfile | 2 +- src/backend/pyproject.toml | 20 ++++++++++---------- 3 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/crowdin_upload.yml b/.github/workflows/crowdin_upload.yml index 000ecca6..bd00d5bc 100644 --- a/.github/workflows/crowdin_upload.yml +++ b/.github/workflows/crowdin_upload.yml @@ -25,8 +25,8 @@ jobs: with: python-version: "3.13.9" cache: 'pip' - - name: Upgrade pip and setuptools - run: pip install --upgrade pip setuptools + - name: Upgrade pip + run: pip install --upgrade pip - name: Install development dependencies run: pip install --user . working-directory: src/backend diff --git a/Dockerfile b/Dockerfile index 04f729fd..21d120fe 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ FROM python:3.13.9-alpine AS base # Upgrade pip to its latest release to speed up dependencies installation # We must do taht to avoid having an outdated pip version with security issues -RUN python -m pip install --upgrade pip setuptools +RUN python -m pip install --upgrade pip # Upgrade system packages to install security updates RUN apk update && \ diff --git a/src/backend/pyproject.toml b/src/backend/pyproject.toml index 3410373f..43ffc379 100644 --- a/src/backend/pyproject.toml +++ b/src/backend/pyproject.toml @@ -2,8 +2,8 @@ # drive package # [build-system] -requires = ["setuptools"] -build-backend = "setuptools.build_meta" +requires = ["uv_build>=0.9.26,<0.10.0"] +build-backend = "uv_build" [project] name = "drive" @@ -21,8 +21,7 @@ classifiers = [ ] description = "An application managing files in a workspace." keywords = ["Django", "Contacts", "Templates", "RBAC"] -license = { file = "LICENSE" } -readme = "README.md" +license = "MIT" requires-python = "~=3.13.0" dependencies = [ "boto3==1.42.19", @@ -92,12 +91,13 @@ dev = [ "types-requests==2.32.4.20250913", ] -[tool.setuptools] -packages = { find = { where = ["."], exclude = ["tests"] } } -zip-safe = true - -[tool.distutils.bdist_wheel] -universal = true +[tool.uv.build-backend] +module-root = "" +source-exclude = [ + "**/tests/**", + "**/test_*.py", + "**/tests.py", +] [tool.ruff] exclude = [