Skip to content

fix: isolate PyPI upload sidecars from verified distributions - #12

Merged
shauneccles merged 2 commits into
mainfrom
fix/isolate-pypi-upload
Oct 5, 2026
Merged

shauneccles merged 2 commits into
mainfrom
fix/isolate-pypi-upload

Conversation

@shauneccles

@shauneccles shauneccles commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

PyPA's publishing action creates .publish.attestation sidecars in its package directory. Those files caused shared GitHub finalization to reject otherwise verified distributions after a successful PyPI upload.

Copy verified distributions into a fresh pypi-dist/ after check-upload, then pass that directory to PyPA. The behavioral regression executes the workflow's staging shell, simulates uploader sidecars, checks original filenames and bytes, and verifies that repeated staging fails without altering either directory.

Pin every shared release-ci action and planning action to the published v0.3.1 release, 442e00705d4e5edd589021851e756761363f9d84, with # v0.3.1 comments. Existing guards require full commit SHAs and matching pins across phases and planning.

Validation: 3 publication contracts passed via the direct CI entry point; all configured hooks passed, including Ruff, actionlint/Shellcheck and zizmor.

@shauneccles
shauneccles merged commit 7c2c138 into main Oct 5, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant