Skip to content

Build reproducibility: pin pytorch_wavelets, recheck the PyTorch 2.1.2 pin, lock dependencies, fix Docker user handling #23

Description

@joeljose

Severity: Medium.

Problems

  1. An unpinned git dependency. Dockerfile.gpu runs pip install git+https://github.com/fbcotter/pytorch_wavelets.git, which installs whatever is on the default branch at build time. That is a reproducibility risk and a supply-chain risk.
  2. The PyTorch pin may no longer be needed. The Dockerfile comment pins pytorch/pytorch:2.1.2-cuda12.1 because pytorch_wavelets "uses old-style autograd.Function". In this audit, current pytorch_wavelets HEAD imported and ran extract_audio_gpu correctly on torch 2.14 (CPU). So the pin (a 2023 base image) may be removable. Please confirm on CUDA.
  3. Inconsistent requirements. requirements-gpu.txt pins numpy<2, while requirements.txt allows <3. PyWavelets has no upper bound. There's no lock file. The CPU image uses opencv-python (needs libgl1/libglib2.0-0), while the GPU image uses the headless build.
  4. The builder's UID is baked into the image. Both Dockerfiles need UID/GID/UNAME build args: a plain docker build . fails, building as root fails, and the images can't be published for other users.
  5. Base image and workflow. python:3.11-slim isn't pinned to a patch release. The workflow has no permissions: block, and actions aren't SHA-pinned.

Suggested fix

  • Install pytorch_wavelets @ git+…@<commit-sha>, or vendor the DTCWT forward pass: only DTCWTForward is used, about 300 lines under MIT licence.
  • Test a current PyTorch base (2.4+), and drop the 2.1.2 pin and numpy<2 if they pass.
  • Keep version ranges in pyproject.toml, generate lock files with uv pip compile, and install from them in Docker and CI.
  • Use opencv-python-headless everywhere.
  • Use a fixed non-root user and document docker run --user "$(id -u):$(id -g)".
  • Add permissions: contents: read, pin actions by SHA, and enable Dependabot.

Acceptance criteria

  • No unpinned VCS dependencies remain.
  • docker build . works with no build args.
  • Builds are reproducible from the lock files.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions