Conversation
…he jobs that hold the PyPI token publish (stable.yml) and publish-dev (dev.yml) pinned build and twine by version only, so their dependencies were whatever was newest that day, and python -m build then downloaded the newest setuptools into an isolated environment. All of it runs next to PYPI_API_TOKEN. Both jobs now install only .github/requirements/publish.txt (wheels only, at recorded hashes, generated from publish.in with uv) and build with python -m build --no-isolation, so the backend is the locked setuptools too. build stays at 1.5.0 and twine at 6.2.0; setuptools is locked at 84.0.0. Dependabot's pip entry names .github/requirements, which it does not reach from the root. test_publish_tooling_lock.py fails when a job with the token runs any other pip install or an isolated build, and when build-system.requires in pyproject.toml or dev.toml asks for something the lock does not pin.
Not up to standards ⛔
|
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Why
The two jobs that receive
secrets.PYPI_API_TOKEN(publishinstable.yml,publish-devindev.yml) pinnedbuildandtwineby version only: no hashes, and their dependencies at whatever was newest that day.python -m buildthen created an isolated environment and downloaded the newestsetuptools. All of that runs in the job that is about to upload with the token.What changes
.github/requirements/publish.inand the generatedpublish.txt:build==1.5.0,twine==6.2.0(the versions the workflows already named) and the build backendsetuptools(locked at 84.0.0), 30 pins in all, wheels only, with hashes, for Python 3.12 onx86_64-manylinux_2_28. Theuv pip compilecommand is at the top ofpublish.in.python -m pip install --require-hashes --only-binary :all: -r .github/requirements/publish.txt, and build withpython -m build --no-isolation, so the backend is the locked one. Triggers, the other steps and the secret are unchanged.release.ymlis unchanged: itsbuildjob has no PyPI token..github/dependabot.yml: thepipentry names/and/.github/requirements, which Dependabot does not reach from the root.test/unit_test/headless/test_publish_tooling_lock.py(11 cases): only those two jobs read the token; each runs exactly the locked install; everypython -m buildin them carries--no-isolation;build-system.requiresinpyproject.tomlanddev.tomlnames only packages the lock pins, at a version inside the specifier;publish.innames exactly what the jobs run plus the backend; the lock is resolved for the Python the jobs set up; Dependabot watches the directory.test_dev_release.pycompares the locked install line and the--no-isolationbuild line of the two jobs instead of thebuild==line.architecture.md,architecture_explore.md,CLAUDE.mdanddocs/updates/(U-20261001-10) describe it.Checked
pip download --require-hashes --only-binary :all: --no-deps).scripts/dev_release.py prepare, 0.0.137), each with--no-isolationand, for comparison, isolated. sdist and wheel build,twine checkpasses, each wheel has 1,062 members with the same names and content as the isolated build's, each sdist the same 1,067 files.je_auto_control_dev0.0.136 only in its version line andRECORD, sopublish-devhas nothing to upload for this change.Not exercised here
Neither publish job runs on a pull request.
publish-devfirst runs its install and build steps on the push that brings this todev;stable.yml'spublishoncedevis merged intomain.