fix(release): publish only verified wheel
prd-number-check / require-numbered-prds (pull_request) Successful in 15s
test / image-input-builds (pull_request) Successful in 42s
test / unit (pull_request) Successful in 56s
test / integration-docker (pull_request) Successful in 1m1s
test / coverage (pull_request) Successful in 15s
tracker-policy-pr / check-pr (pull_request) Failing after 12m49s

This commit is contained in:
2026-07-27 16:21:57 +00:00
parent d8c5532168
commit a2113b7f43
2 changed files with 8 additions and 5 deletions
+4 -3
View File
@@ -51,17 +51,18 @@ jobs:
- name: Build package with assigned infrastructure pins
env:
BOT_BOTTLE_RELEASE_MANIFEST: ${{ github.workspace }}/release-manifest.json
run: python3 -m build
run: python3 -m build --wheel
- name: Verify packaged manifest
run: |
test "$(find dist -maxdepth 1 -name '*.whl' -type f | wc -l)" -eq 1
python3 -m venv verify-venv
verify-venv/bin/pip install --no-deps dist/*.whl
verify-venv/bin/python -c \
'from bot_bottle.release_manifest import load_manifest; print(load_manifest())'
- name: Upload release package
- name: Upload verified release wheel
uses: actions/upload-artifact@v3
with:
name: bot-bottle-release
path: dist/
path: dist/*.whl
+4 -2
View File
@@ -127,10 +127,12 @@ The release job operates on one tested commit:
4. Publish both generic-package artifacts and retain their versions and
compressed-file checksums.
5. Generate `release-manifest.json` from those published identities.
6. Build the wheel/sdist with that manifest.
6. Build the wheel with that manifest. Do not produce a source distribution:
rebuilding an sdist outside this release boundary could replace the pins
with the development manifest.
7. Install the wheel in a clean environment and assert that every manifest
identity is valid and retrievable.
8. Publish the Python distribution.
8. Publish only that verified wheel.
The build hook receives the manifest as a file input. It must not query a
registry or choose versions itself: package builds stay deterministic and