fix(release): publish only verified wheel
prd-number-check / require-numbered-prds (pull_request) Successful in 15s
test / image-input-builds (pull_request) Successful in 42s
test / unit (pull_request) Successful in 56s
test / integration-docker (pull_request) Successful in 1m1s
test / coverage (pull_request) Successful in 15s
tracker-policy-pr / check-pr (pull_request) Failing after 12m49s
prd-number-check / require-numbered-prds (pull_request) Successful in 15s
test / image-input-builds (pull_request) Successful in 42s
test / unit (pull_request) Successful in 56s
test / integration-docker (pull_request) Successful in 1m1s
test / coverage (pull_request) Successful in 15s
tracker-policy-pr / check-pr (pull_request) Failing after 12m49s
This commit is contained in:
@@ -51,17 +51,18 @@ jobs:
|
||||
- name: Build package with assigned infrastructure pins
|
||||
env:
|
||||
BOT_BOTTLE_RELEASE_MANIFEST: ${{ github.workspace }}/release-manifest.json
|
||||
run: python3 -m build
|
||||
run: python3 -m build --wheel
|
||||
|
||||
- name: Verify packaged manifest
|
||||
run: |
|
||||
test "$(find dist -maxdepth 1 -name '*.whl' -type f | wc -l)" -eq 1
|
||||
python3 -m venv verify-venv
|
||||
verify-venv/bin/pip install --no-deps dist/*.whl
|
||||
verify-venv/bin/python -c \
|
||||
'from bot_bottle.release_manifest import load_manifest; print(load_manifest())'
|
||||
|
||||
- name: Upload release package
|
||||
- name: Upload verified release wheel
|
||||
uses: actions/upload-artifact@v3
|
||||
with:
|
||||
name: bot-bottle-release
|
||||
path: dist/
|
||||
path: dist/*.whl
|
||||
|
||||
@@ -127,10 +127,12 @@ The release job operates on one tested commit:
|
||||
4. Publish both generic-package artifacts and retain their versions and
|
||||
compressed-file checksums.
|
||||
5. Generate `release-manifest.json` from those published identities.
|
||||
6. Build the wheel/sdist with that manifest.
|
||||
6. Build the wheel with that manifest. Do not produce a source distribution:
|
||||
rebuilding an sdist outside this release boundary could replace the pins
|
||||
with the development manifest.
|
||||
7. Install the wheel in a clean environment and assert that every manifest
|
||||
identity is valid and retrievable.
|
||||
8. Publish the Python distribution.
|
||||
8. Publish only that verified wheel.
|
||||
|
||||
The build hook receives the manifest as a file input. It must not query a
|
||||
registry or choose versions itself: package builds stay deterministic and
|
||||
|
||||
Reference in New Issue
Block a user