Repository navigation
#76: publish releases to PyPI, with a TestPyPI rehearsal - #79
Draft
craigmcchesney wants to merge 1 commit into
Draft
craigmcchesney wants to merge 1 commit into
craigmcchesney wants to merge 1 commit into
Conversation
- release.yml: enable publish-pypi on rel-* tags, after the GitHub Release (needs publish-github-release), with skip-existing and a post-upload digest check against SHA256SUMS. New publish-testpypi job behind a testpypi dispatch input; dispatch builds drop the local version segment. release-dist retention 7 -> 30 days to match the approval window. - .github/scripts/check-index-digests.py: the digest check (self-tested). - pyproject.toml: Documentation and Changelog URLs. - README: lead with pip install from PyPI, quoted extras, absolute links. - README.env: installing from PyPI and verifying a pip download. - Cookbook: quote the extras. NEXT.md: #76 section, Installing, and the approval step in the cut checklist. CLAUDE.md: the enabled flow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UCxWh2HqjqhsmLwSJbJAWE
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 2
Open (2)
What changed in this PR
This PR enables publishing signed release artifacts to PyPI/TestPyPI via Trusted Publishing and updates project documentation to reflect PyPI installation and verification guidance.
Changes:
- Enable PyPI publishing (and optional TestPyPI rehearsal) in the release workflow, including a post-upload digest verification step.
- Add a digest-checking script to confirm PyPI serves exactly the signed artifacts.
- Update READMEs/cookbook/release notes to document PyPI installs, quoting extras, and verification steps.
| File | Description |
|---|---|
| pyproject.toml | Adds Documentation/Changelog project URLs for better package metadata. |
| plan/tickets/76/plan.md | Updates Issue #76 plan status and implementation notes for digest checking. |
| doc/release-notes/NEXT.md | Adds release-notes section and checklist updates for PyPI publishing flow. |
| doc/cookbook/query.md | Quotes extras in pip install command to avoid zsh globbing. |
| doc/cookbook/conventions.md | Same extras quoting fix in conventions recipe. |
| doc/cookbook/README.md | Quotes editable extras install for zsh compatibility. |
| README.md | Updates install instructions to PyPI and fixes links for non-GitHub renderers. |
| README.env | Adds “Installing from PyPI” verification instructions and updates notes. |
| CLAUDE.md | Updates release workflow documentation and examples to include PyPI publish path. |
| .github/workflows/release.yml | Enables publish jobs for PyPI/TestPyPI and adds digest verification + longer artifact retention. |
| .github/scripts/check-index-digests.py | New script to compare SHA256SUMS against the index JSON API digests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if not line.strip(): | ||
| continue | ||
| digest, name = line.split(maxsplit=1) | ||
| sums[name.lstrip("*")] = digest.lower() |
Comment on lines
+108
to
+115
| set -euo pipefail | ||
| # A rehearsal builds an untagged commit, which setuptools-scm versions with a local | ||
| # segment (1.16.1.dev61+g496f0e0). PyPI and TestPyPI both reject local versions, so | ||
| # a dispatch drops it (1.16.1.dev61) to stay uploadable to TestPyPI. A tag build has | ||
| # no local segment and is left alone. | ||
| if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then | ||
| export SETUPTOOLS_SCM_OVERRIDES_FOR_DP_PYTHON_LIB='{local_scheme="no-local-version"}' | ||
| fi |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Closes #76. Implements
plan/tickets/76/plan.md(merged in #78).Draft until the manual setup is done. Do not merge before manual steps 1–3 of the plan:
pending trusted publishers on pypi.org (environment
pypi) and test.pypi.org (environmenttestpypi),and the
pypiGitHub environment with its required reviewer, "prevent self-review" off, and arel-*tag rule. A job naming a missing environment creates it unprotected.
Changes
release.ymlpublish-pypiis enabled onrel-*tag pushes, withneeds: [build, publish-github-release](D4).skip-existing: true(D3a).SHA256SUMS(D5).publish-testpypijob behind atestpypidispatch input (D3).1.16.1.dev66).release-distretention goes from 7 to 30 days (D2)..github/scripts/check-index-digests.py: the digest check, which self-tests on each run..github/scriptsfor it, which addscontents: read.sigstore3.5.0): it passes on matching files, fails on a changed digest, and fails on a version the index doesn't have.pyproject.toml:DocumentationandChangelogURLs (D7).pip install dp-python-liband uses quoted extras and absoluteblob/mainlinks.--no-deps/--ignore-missingrecipe.NEXT.mdgets a Publish releases to PyPI (enable the disabled publish-pypi job) #76 section, an updated## Installing, and an approval step in the cut checklist.Verification
ruff check,ruff format --check,mypy src/, cookbook checker (129 snippets), release-notes checker,pytest tests/unit(968 passed).1.16.1.dev66;twine check --strictpasses.testpypi=true.pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ "dp-python-lib==<dev version>"installs and importsMldpClient.testpypi=falsestops after build/sign, with both publish jobs skipped.🤖 Generated with Claude Code
https://claude.ai/code/session_01UCxWh2HqjqhsmLwSJbJAWE