Skip to content

Releasing with a VERSION file has a footgun #155

Description

@ktbarrett

If you have a version_file setup and push a tag, the release template that pull in the version info from the file will be used regardless of the value of that tag. We just encountered an issue where we were trying to release an rc prerelease package, so we pushed a tag v2.1.0rc1 and this created the package 2.1.0 by looking directly at the VERSION file. This is definitely on us since we had an LLM cook up the scripts and didn't see through it's faulty assumptions.

I think what we want is the tag be compared against the called out version in the version_file; see that it is compatible since it's a pre, final, or post release; and then use the tag's value over the VERSION file. But in cases where there is no tag, it uses the VERSION file with the derived dev count in the dev template. I would expect we would have to fill in tag_formatter (since tags are currently v{version}) or switch to using the actual PEP compliant version number as the tag.

That all can be accomplished right now with a custom version callback. My questions are.

  1. Should what I described be standard behavior?
  2. Maybe optional behavior behind a flag?
  3. Instead of 1 or in addition to 2, I feel there needs to be a strict check that the tag and version are equal, just to prevent this footgun from shooting someone else.

Activity

  1. dolfinus commented on Aug 31, 2026

    @dolfinus
    Owner

    Hi.

    Should what I described be standard behavior?

    version_file documentation says:
    Please take into account that any tags in the repo are ignored if this option is being used.

    Maybe optional behavior behind a flag?

    It can be an option prefer_tag: bool, for this use case.

    I feel there needs to be a strict check that the tag and version are equal

    This can break current repos. IMHO there should be a warning if tag and version file content are not the same.

  2. dolfinus commented on Sep 30, 2026

    @dolfinus
    Owner

    One more question - why version_file schema is used in the first place, if you rely on git tag for versioning?

  3. ktbarrett commented on Sep 30, 2026

    @ktbarrett
    Author

    One more question - why version_file schema is used in the first place, if you rely on git tag for versioning?

    Shallow clones in CI for non-releases and no guessing about what the next release version is (which is what we particularly disliked about setuptools-scm).

  4. dolfinus commented on Oct 5, 2026

    @dolfinus
    Owner

    Fixed in #162

  5. dolfinus commented on Oct 5, 2026

    @dolfinus
    Owner

    This is now a part of 3.2.0 release

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions