Skip to content

fix: isolate PyPI upload sidecars from verified distributions - #14

Merged
shauneccles merged 1 commit into
mainfrom
fix/isolate-pypi-upload
Oct 5, 2026
Merged

shauneccles merged 1 commit into
mainfrom
fix/isolate-pypi-upload

Conversation

@shauneccles

Copy link
Copy Markdown
Member

PyPA's publishing action creates .publish.attestation files in its package directory. This caused shared GitHub finalization to reject unexpected files after the sender's successful PyPI upload.

Copy verified distributions into a fresh pypi-dist/ after check-upload, then pass that directory to PyPA. Every shared phase and GitHub attestation continues using the unchanged dist/. Plain mkdir refuses an existing staging directory; hash, provenance and release-identity checks remain intact.

Update the shared example and documentation with the same integration. Remove stale claims that Aubio still has a TestPyPI lane; production-only publishing remains the documented policy.

Validation: Full shared suite: 255 passed; all configured hooks and final documentation checks passed. The behavioral regression executes the actual staging shell, simulates uploader sidecars, checks original filenames and bytes, and verifies that repeated staging fails without modifying either directory.

@shauneccles
shauneccles merged commit f88cea3 into main Oct 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant