Skip to content

[medium] Pin plugin upgrade to the compatible release and re-check pySigma - #103

Open
elhoim wants to merge 1 commit into
SigmaHQ:mainfrom
elhoim:fix/plugin-upgrade-compatible-release
Open

elhoim wants to merge 1 commit into
SigmaHQ:mainfrom
elhoim:fix/plugin-upgrade-compatible-release

Conversation

@elhoim

@elhoim elhoim commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

BLUF

  • Problem: sigma plugin upgrade with the compatibility check (the default) only checks that some release of a plugin supports the installed pySigma. It then runs an unpinned pip install --upgrade <package>, which installs the newest release. The newest release may require a different pySigma major.
  • Impact: once a plugin publishes a release for pySigma 2.x, a plain sigma plugin upgrade installs it, and pip upgrades pySigma to satisfy it. This can break sigma-cli (pysigma>=1.3.0,<2.0.0), and unlike plugin install, upgrade never runs the pySigma re-check.
  • Fix:
    • With the compatibility check on, upgrade calls SigmaPlugin.install(), which pins package==<newest compatible release>.
    • --no-compatibility-check keeps the unpinned pip install --upgrade.
    • New --check-pysigma/--no-check-pysigma option (default on), matching plugin install, re-checks pySigma after upgrading.
  • Tests: two new offline tests with PyPI, pip and the plugin directory stubbed. The compatible-release test fails on main and passes with the fix.

Priority: medium

Details

Root cause: sigma/cli/plugin.py:158-169

if not compatibility_check or plugin.is_compatible():
    plugin.upgrade()
  • SigmaPlugin.is_compatible() (pySigma plugins.py) returns True if find_compatible_version() finds any compatible release on PyPI.
  • SigmaPlugin.install() pins the newest compatible release: package==<find_compatible_version()>.
  • SigmaPlugin.upgrade() runs pip install --upgrade <package> with no version constraint. The version the check found is never used.

install() is also the right upgrade path. pip install package==X upgrades an installed older release to X, which is the newest release that works with the installed pySigma.

Example, with pySigma 1.4.0 installed. pysigma-backend-demo 1.0.0 requires pySigma <2, 2.0.0 requires >=2:

pip call
before pip install --upgrade pysigma-backend-demo (resolves to 2.0.0, pulls pySigma 2.x)
after pip install pysigma-backend-demo==1.0.0, then the pySigma version check

Testing

  • New tests in tests/test_plugin.py. They are offline: SigmaPlugin._get_pypi_json, SigmaPlugin.is_installed, subprocess.check_call, the plugin directory and check_pysigma_command are stubbed.
    • test_plugin_upgrade_installs_compatible_release (fails on main)
    • test_plugin_upgrade_without_compatibility_check
  • Full suite, run the way CI runs it (Python 3.12, dependencies pinned to poetry.lock: pySigma 1.4.0, click 8.4.2, pyparsing 3.3.2): pytest --cov=sigma → 120 passed, 1 skipped.

🤖 Generated with Claude Code

With the compatibility check enabled, 'sigma plugin upgrade' only verified that SOME release of a plugin is compatible with the installed pySigma version and then ran an unpinned 'pip install --upgrade', which installs the newest release even if it requires another pySigma version. Unlike 'plugin install' it also never re-checked the pySigma version afterwards.

With the compatibility check, upgrade now installs the newest compatible release (SigmaPlugin.install(), which pins it). --no-compatibility-check keeps the unpinned upgrade. A --check-pysigma/--no-check-pysigma option (default on, as for install) re-checks pySigma after upgrading.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

--check-pysigma currently runs even when no plugins were upgraded/installed (potentially prompting/output on a no-op run), which is surprising and doesn’t match the “check after plugin upgrade” behavior implied by the option/help text.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

This PR fixes sigma plugin upgrade so that, when compatibility checking is enabled, it upgrades plugins by installing the newest compatible plugin release (pinned) instead of doing an unpinned pip install --upgrade that can pull in an incompatible pySigma major; it also adds an optional post-upgrade pySigma re-check consistent with plugin install.

Changes:

  • Update plugin upgrade to use SigmaPlugin.install() (pinned to newest compatible release) when compatibility check is enabled.
  • Add --check-pysigma/--no-check-pysigma (default on) to re-check pySigma after upgrades.
  • Add offline tests covering compatible-release pinning and the --no-compatibility-check behavior.
File Description
sigma/​cli/​plugin.py Adjusts upgrade behavior to install the newest compatible plugin release and adds optional pySigma re-check.
tests/​test_plugin.py Adds offline tests validating pinned compatible upgrades and the no-compatibility-check path.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread sigma/cli/plugin.py
Comment on lines +183 to +184
if check_pysigma:
check_pysigma_command()
Comment thread sigma/cli/plugin.py
if not compatibility_check or plugin.is_compatible():
if not compatibility_check:
plugin.upgrade()
click.echo(f"Successfully upgrade plugin '{plugin.id}'")

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants