Conversation
With the compatibility check enabled, 'sigma plugin upgrade' only verified that SOME release of a plugin is compatible with the installed pySigma version and then ran an unpinned 'pip install --upgrade', which installs the newest release even if it requires another pySigma version. Unlike 'plugin install' it also never re-checked the pySigma version afterwards. With the compatibility check, upgrade now installs the newest compatible release (SigmaPlugin.install(), which pins it). --no-compatibility-check keeps the unpinned upgrade. A --check-pysigma/--no-check-pysigma option (default on, as for install) re-checks pySigma after upgrading. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
--check-pysigma currently runs even when no plugins were upgraded/installed (potentially prompting/output on a no-op run), which is surprising and doesn’t match the “check after plugin upgrade” behavior implied by the option/help text.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR fixes sigma plugin upgrade so that, when compatibility checking is enabled, it upgrades plugins by installing the newest compatible plugin release (pinned) instead of doing an unpinned pip install --upgrade that can pull in an incompatible pySigma major; it also adds an optional post-upgrade pySigma re-check consistent with plugin install.
Changes:
- Update
plugin upgradeto useSigmaPlugin.install()(pinned to newest compatible release) when compatibility check is enabled. - Add
--check-pysigma/--no-check-pysigma(default on) to re-check pySigma after upgrades. - Add offline tests covering compatible-release pinning and the
--no-compatibility-checkbehavior.
| File | Description |
|---|---|
sigma/cli/plugin.py |
Adjusts upgrade behavior to install the newest compatible plugin release and adds optional pySigma re-check. |
tests/test_plugin.py |
Adds offline tests validating pinned compatible upgrades and the no-compatibility-check path. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if check_pysigma: | ||
| check_pysigma_command() |
| if not compatibility_check or plugin.is_compatible(): | ||
| if not compatibility_check: | ||
| plugin.upgrade() | ||
| click.echo(f"Successfully upgrade plugin '{plugin.id}'") |


BLUF
sigma plugin upgradewith the compatibility check (the default) only checks that some release of a plugin supports the installed pySigma. It then runs an unpinnedpip install --upgrade <package>, which installs the newest release. The newest release may require a different pySigma major.sigma plugin upgradeinstalls it, and pip upgrades pySigma to satisfy it. This can break sigma-cli (pysigma>=1.3.0,<2.0.0), and unlikeplugin install, upgrade never runs the pySigma re-check.SigmaPlugin.install(), which pinspackage==<newest compatible release>.--no-compatibility-checkkeeps the unpinnedpip install --upgrade.--check-pysigma/--no-check-pysigmaoption (default on), matchingplugin install, re-checks pySigma after upgrading.mainand passes with the fix.Priority: medium
Details
Root cause:
sigma/cli/plugin.py:158-169SigmaPlugin.is_compatible()(pySigmaplugins.py) returnsTrueiffind_compatible_version()finds any compatible release on PyPI.SigmaPlugin.install()pins the newest compatible release:package==<find_compatible_version()>.SigmaPlugin.upgrade()runspip install --upgrade <package>with no version constraint. The version the check found is never used.install()is also the right upgrade path.pip install package==Xupgrades an installed older release to X, which is the newest release that works with the installed pySigma.Example, with pySigma 1.4.0 installed.
pysigma-backend-demo1.0.0 requires pySigma<2, 2.0.0 requires>=2:pip install --upgrade pysigma-backend-demo(resolves to 2.0.0, pulls pySigma 2.x)pip install pysigma-backend-demo==1.0.0, then the pySigma version checkTesting
tests/test_plugin.py. They are offline:SigmaPlugin._get_pypi_json,SigmaPlugin.is_installed,subprocess.check_call, the plugin directory andcheck_pysigma_commandare stubbed.test_plugin_upgrade_installs_compatible_release(fails onmain)test_plugin_upgrade_without_compatibility_checkpoetry.lock: pySigma 1.4.0, click 8.4.2, pyparsing 3.3.2):pytest --cov=sigma→ 120 passed, 1 skipped.🤖 Generated with Claude Code