Skip to content

fix(ci): verify PyPI releases through the install index - #40

Merged
fancyboi999 merged 2 commits into
mainfrom
fix/pypi-index-verification
Oct 10, 2026
Merged

fancyboi999 merged 2 commits into
mainfrom
fix/pypi-index-verification

Conversation

@fancyboi999

@fancyboi999 fancyboi999 commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

改动描述

PyPI 发布回读改用官方 Simple JSON 安装索引,验证已上传文件哈希和真实 CLI/MCP;上传与既有工件冲突门槛保留。校验最多 10 次有限重试,verify job 限时 15 分钟。

动机 / 关联 issue

PR #38 的程序已自动生成并合并 #39、生成 v0.5.1 并通过 OIDC 上传两个 0.5.1 文件。实际 publisher run 38017125709 的 verify job 连续收到版本 JSON 路由 404,导致整体失败;随后项目 JSON、版本 JSON 和安装索引均列出真实 0.5.1 文件。完整缓存传播机制未证明,不将其猜测当根因。

安装可用性由项目已有的 Simple 安装索引表达,避免将新版本 JSON 路由可见性当成消费边界;使用官方 PEP 691 内容协商与哈希字段。不是跳过验证、直接改判成功或重复上传。CI 与 publisher 的质量检查同时锁定触发 commit 的完整 SHA,避免不同 job 读取移动 ref 而验证不同源代码。

改动类型

  • bug 修复
  • 新功能
  • 重构(不改变外部行为)
  • 文档
  • CI / 构建

验证

  • ruff、actionlint、版本契约及 git diff --check 通过
  • 使用原工作流 0.5.1 dist,对真实 Simple JSON 索引核对两文件 SHA256
  • 从 PyPI 安装 0.5.1:CLI 版本、MCP 握手及 17 工具目录通过
  • 损坏工件控制仍立即拒绝,没有替换网络响应或新增单测/mock
python scripts/verify_pypi_release.py 0.5.1 --dist <工作流dist>
artifact_hashes_match=true, cli_version_verified=true, mcp_handshake=true, tool_count=17

合入后继续通过程序自身生成的下一补丁发布验证完整 Actions 链路;ClawHub 保持手动,不上传。

合规

  • 未提交 cookie、token 或账号/会话敏感材料
  • 不增加业务写操作,不绕过发布或平台安全检查

@fancyboi999
fancyboi999 merged commit d9dfc78 into main Oct 10, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant