juniper-ci-tools
Shared CI / build tooling for the Juniper ML platform.
This package is the single source of truth for the dependency-documentation
generator that historically lived as scripts/generate_dep_docs.sh (or
util/generate_dep_docs.sh) in every Juniper repo. Three variants of that
script drifted on origin/main; the 2026-05-20 bug fix in
juniper-cascor#276
(switching the conda-dependency extraction from sed to awk to avoid
emitting an invalid trailing prefix: / variables: key) shipped in 1 of 8
repos. This package distributes that fix as pip install-able tooling so it
cannot drift again.
This work mirrors the
juniper-doc-tools PyPI migration plan
that addressed the analogous 2026-05-18 doc-link validator incident.
Installation
pip install juniper-ci-tools
This installs the following console scripts (see the package's
[project.scripts] for the authoritative set):
juniper-generate-dep-docs— dependency-documentation generator (the consolidatedscripts/generate_dep_docs.shport; see "Usage" below).juniper-lint-workflow-paths— lints that everypython|bash <path>invocation in.github/workflows/*.ymlreferences a file that exists on disk. Added in 0.2.0; consolidates the 6 byte-identical copies ofutil/test_workflow_script_paths.pythat existed across consumer repos.juniper-lint-agents-md-version— lints that theAGENTS.md**Version**:header matchespyproject.toml[project].version(added in 0.3.0).juniper-lint-agents-md-header— lints theAGENTS.mdcanonical six-field header schema (added in 0.4.0).juniper-coverage-gap-map— advisory per-file coverage-gap mapper (added in 0.5.0): parses acoverage jsonand reports the per-file distribution, the files below a threshold (default 90 %), and each sub-module's average vs a bar (default 95 %). Exit 0 always — it reports, it never fails a build. Carries a documented numpy-2.x package-form--covshim.
The package requires Python 3.11 or newer and depends on PyYAML and packaging.
Usage
Run from the root of any Juniper repo that has a pyproject.toml:
juniper-generate-dep-docs
Equivalent module form:
python -m juniper_ci_tools
This will:
- Create
conf/if needed. - Back up any existing
conf/requirements_ci.txtwith a timestamp infix. - Render
notes/PIP_DEPENDENCY_FILE_HEADER.md(substituting placeholders like<X.Y.Z ...>,<YYYY-MM-dd ...>,<Python Version>,<Pip Version>) and appendpip list --format=freezeoutput. - If
condais onPATH: back up any existingconf/conda_environment_ci.yaml, rendernotes/CONDA_DEPENDENCY_FILE_HEADER.md, append the dependency block extracted fromconda env export --no-builds(using the awk-equivalent logic that produces valid YAML), and validate the result withyaml.safe_load.
If conda is not available the conda step is skipped with a warning (matches the legacy bash script). If the generated YAML fails to parse, the command exits non-zero.
CLI options
| Flag | Default | Purpose |
|---|---|---|
--repo-root |
cwd | Repo root containing pyproject.toml |
--conf-dir |
conf |
Output directory |
--notes-dir |
notes |
Directory containing header templates |
--pip-header |
PIP_DEPENDENCY_FILE_HEADER.md |
Pip header template filename |
--conda-header |
CONDA_DEPENDENCY_FILE_HEADER.md |
Conda header template filename |
--pip-filename |
requirements_ci.txt |
Pip output filename |
--conda-filename |
conda_environment_ci.yaml |
Conda output filename |
--no-conda |
off | Skip conda generation even if conda is installed |
--no-yaml-validation |
off | Skip yaml.safe_load on generated conda file |
Environment floor-drift check (juniper-env-drift-check)
Run from (or against) any Juniper repo to assert the active environment is not
below the client floors the repo's pyproject.toml declares — the durable,
reusable form of the dependency-satisfaction guard (added in 0.5.0). Unlike
util/editable_install_drift_check.py, it reads versions via
importlib.metadata, so plain wheels are checked identically to editable
installs (the 2026-06-26 canopy "green tests / dead app" incident class).
# Scan the active interpreter against ./pyproject.toml
juniper-env-drift-check
# Check a specific repo, and also assert its lockfile pins satisfy the floors
juniper-env-drift-check --repo-root /path/to/repo --check-lock
# Scan a specific environment's site-packages (e.g. a conda env), as JSON
juniper-env-drift-check --site-packages /opt/miniforge3/envs/MyEnv/lib/python3.13/site-packages --json
Exit codes: 0 (no floor below its requirement), 1 (drift — an installed
wheel, or a --check-lock lock pin, below a floor), 2 (usage error — no
pyproject.toml, no juniper-* floors, or --check-lock with no lockfile). A
not-installed floor is a soft note unless --strict is given. Every floor (OK
and drifted alike) is listed — no silent truncation.
Library API
from juniper_ci_tools import generate_dep_docs
result = generate_dep_docs(repo_root="/path/to/repo")
print(result.pip_file, result.conda_file, result.yaml_validated)
See the package's juniper_ci_tools/generate_dep_docs.py docstring for the
full surface.
Development
cd juniper-ci-tools
pip install -e ".[test]"
pytest
License
MIT. Copyright (c) 2024-2026 Paul Calnon.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file juniper_ci_tools-0.5.0.tar.gz.
File metadata
- Download URL: juniper_ci_tools-0.5.0.tar.gz
- Upload date:
- Size: 57.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a40d62685cdc5340f0657568a02f9b4b11b03bdf31c541548e7d3a5f6dd3b37e
|
|
| MD5 |
08749f908d038ea936f70f54306cd72d
|
|
| BLAKE2b-256 |
2a72efc9471f1cc382c3de86f7621f801563f86a8147ffd4447ed4936fa8349c
|
Provenance
The following attestation bundles were made for juniper_ci_tools-0.5.0.tar.gz:
Publisher:
publish-ci-tools.yml on pcalnon/juniper-ml
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juniper_ci_tools-0.5.0.tar.gz -
Subject digest:
a40d62685cdc5340f0657568a02f9b4b11b03bdf31c541548e7d3a5f6dd3b37e - Sigstore transparency entry: 2015412816
- Sigstore integration time:
-
Permalink:
pcalnon/juniper-ml@f2ce007b1d6ff9e07c0a509423e737ea36e48270 -
Branch / Tag:
refs/tags/juniper-ci-tools-v0.5.0 - Owner: https://github.com/pcalnon
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-ci-tools.yml@f2ce007b1d6ff9e07c0a509423e737ea36e48270 -
Trigger Event:
release
-
Statement type:
File details
Details for the file juniper_ci_tools-0.5.0-py3-none-any.whl.
File metadata
- Download URL: juniper_ci_tools-0.5.0-py3-none-any.whl
- Upload date:
- Size: 47.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
28b27a7865a23c237fe46eeb9938d96d6d843f6f6bbf789b3a4a47cf0bad3eb5
|
|
| MD5 |
69d2e6f2418f5fbcea9d1ecb62c75aee
|
|
| BLAKE2b-256 |
7389f1830073467e98bf6d1bc6d63455470b1a0fa937c57e0281fc0226d2e975
|
Provenance
The following attestation bundles were made for juniper_ci_tools-0.5.0-py3-none-any.whl:
Publisher:
publish-ci-tools.yml on pcalnon/juniper-ml
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juniper_ci_tools-0.5.0-py3-none-any.whl -
Subject digest:
28b27a7865a23c237fe46eeb9938d96d6d843f6f6bbf789b3a4a47cf0bad3eb5 - Sigstore transparency entry: 2015412955
- Sigstore integration time:
-
Permalink:
pcalnon/juniper-ml@f2ce007b1d6ff9e07c0a509423e737ea36e48270 -
Branch / Tag:
refs/tags/juniper-ci-tools-v0.5.0 - Owner: https://github.com/pcalnon
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-ci-tools.yml@f2ce007b1d6ff9e07c0a509423e737ea36e48270 -
Trigger Event:
release
-
Statement type: