Skip to content

Add notice when test-smokes runs without dev knitr/rmarkdown - #15012

Merged
cderv merged 1 commit into
mainfrom
feature/test-smokes-dev-install-presence-check
Oct 9, 2026
Merged

cderv merged 1 commit into
mainfrom
feature/test-smokes-dev-install-presence-check

Conversation

@cderv

@cderv cderv commented Oct 9, 2026

Copy link
Copy Markdown
Member

The Restore R packages step in test-smokes.yml installs the dev versions of rmarkdown and knitr from r-universe inside try(). When this install fails, the version restored by renv stays in place and the tests run against the CRAN release with nothing in the log, so a run can look like it tested dev versions when it did not.

Failing the step was considered but would not catch anything. Both packages are in tests/renv.lock and the step already stops when renv::status() is not synchronized. In my tests (R 4.6, Windows binaries), a failed install.packages() leaves the existing version installed: an unreachable repo only warns and falls back to CRAN from repos, and a corrupt archive errors but keeps the previous install. Falling back to CRAN is also the expected tolerance for r-universe flakiness.

So after the install, the step now reads the Repository field from each package DESCRIPTION and emits a ::notice:: with the version and source in use when it is not an r-universe URL:

::notice::Dev version of knitr not installed; tests use 1.52 from CRAN

The source is compared rather than the version, so there is no false positive when dev and CRAN versions are the same right after a release.

I checked the snippet locally against a library with CRAN versions (one notice per package) and one with r-universe versions (no output).

Checklist

I have (if applicable):

  • referenced the GitHub issue this PR closes
  • updated the appropriate changelog in the PR
  • ensured the present test suite passes
  • added new tests
  • created a separate documentation PR in Quarto's website repo and linked it to this PR
AI-assisted PR
  • AI tool used: Claude Code
  • Codebase grounding: local clone
  • Human review: I have reviewed, tested, and verified the AI-generated content before submitting.

Note: autonomous AI agents submitting PRs without human oversight are not permitted — see the Code of Conduct.

The Restore R packages step installs dev rmarkdown and knitr from
r-universe inside try(). When that install fails, the renv-restored CRAN
version stays installed and the tests silently run against it, so a run
can look like it tested dev versions when it did not.

Failing setup here would not help: both packages are in renv.lock and the
step already stops if renv::status() is not synchronized, and a failed
install.packages() leaves the existing version in place (an unreachable
repo only warns and falls back to CRAN; a corrupt archive errors but keeps
the old install). Falling back is the intended tolerance for r-universe
flakiness.

Instead, check the DESCRIPTION Repository field after the install and emit
a ::notice:: naming the version and source in use when it is not an
r-universe URL. Comparing the source rather than the version avoids a
false positive when the dev and CRAN versions coincide right after a
release.
@posit-snyk-bot

posit-snyk-bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@cderv
cderv merged commit b976544 into main Oct 9, 2026
50 of 51 checks passed
@cderv
cderv deleted the feature/test-smokes-dev-install-presence-check branch October 9, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants