Repository navigation
fix(ci): automate verified PyPI releases; keep ClawHub manual - #38
Merged
Merged
Conversation
9 of 11 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
改动描述
业务 PR 合入 main 后,程序维护发布 PR、同步版本和 CHANGELOG,验证后自动合并、生成 tag/GitHub Release并触发 PyPI。ClawHub 保持手动,不配置其 token 或上传步骤。
动机 / 关联 issue
现有 publisher 只在手工 tag/dispatch 后构建上传,缺少自动版本准备及相同提交的 CI 门槛。PR #36 的功能修复、PR #37 的 0.5.0 与 ClawHub 0.5.0 均已发布;这里实现后续 PyPI 自动化。
release-please 管理版本语义和多处元数据。自动合并只接受本仓库 Actions 生成的发布 PR,冻结并验证 SHA、main 基线、版本字段范围;候选更新或 main 前进时中止。GITHUB_TOKEN 创建的 tag 不依赖 push 级联,而是显式 dispatch 原 publish.yml,以保留现有 PyPI Trusted Publisher 身份。无需个人访问 token。
publisher 只接受匹配元数据且属于 main 的稳定 tag;完整 CI 后检查已存在工件哈希,用 OIDC 上传,并由另一个无 id-token 权限的 job 从 PyPI 安装验证 CLI/MCP。相同字节才允许跳过已上传文件,冲突拒绝。
改动类型
验证
未新增单元测试或 mock;负向实验仅在任务目录,未提交。GitHub Actions 实际生成/合并发布 PR、dispatch 及新的 PyPI 发布将在本 PR 合入后验证,当前不宣称已跑通。仓库需允许 Actions 创建 PR,默认 workflow 权限仍保持 read,写权限只在对应 job 声明;不绕过 branch protection。ClawHub 新版仍按 CONTRIBUTING.md 手工验收和发布。
合规