Skip to content

Support pySigma 2.0 - #85

Draft
cristianchiriac wants to merge 1 commit into
SigmaHQ:mainfrom
cristianchiriac:pysigma-2
Draft

cristianchiriac wants to merge 1 commit into
SigmaHQ:mainfrom
cristianchiriac:pysigma-2

Conversation

@cristianchiriac

Copy link
Copy Markdown
Contributor

pySigma 2.0.0 was released on 2026-10-04. The backend requires pysigma = "^1", so it can't be installed together with it.

Changes

  • pyproject.toml: pysigma = "^2". pySigma 2.0 requires Python ≥ 3.11, so python = "^3.11" and 3.10 is dropped from the test matrix.
  • poetry.lock regenerated with poetry lock (Poetry 2.1.3, same as the existing lock header). Every resolved change comes from pySigma 2.0's own requirements: pysigma 1.2.0 → 2.0.0, new google-re2 and jq, packaging 25.0 → 26.3 and types-pyyaml (raised minimums), and exceptiongroup/tomli removed (3.10-only).

No code changes were needed: with pySigma 2.0.0 on Python 3.11, the full suite passes (160 passed).

Note on CI: poetry install installs the backend in editable mode, and with pySigma 2.0.0 the editable package can't be imported (ModuleNotFoundError: No module named 'sigma.backends.splunk'). That is the regression in SigmaHQ/pySigma#584, which also has the fix. I ran the tests above against a regular (non-editable) install. Until #584 is released, the test jobs here will fail at import, so I'm opening this as a draft.

pySigma 2.0.0 requires Python 3.11, so drop 3.10 from the supported
versions and the test matrix. poetry.lock was regenerated with Poetry
2.1.3; the changes come from pySigma 2.0's own requirements.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant