Repository navigation
fix(ci): verify PyPI releases through the install index - #40
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
改动描述
PyPI 发布回读改用官方 Simple JSON 安装索引,验证已上传文件哈希和真实 CLI/MCP;上传与既有工件冲突门槛保留。校验最多 10 次有限重试,verify job 限时 15 分钟。
动机 / 关联 issue
PR #38 的程序已自动生成并合并 #39、生成 v0.5.1 并通过 OIDC 上传两个 0.5.1 文件。实际 publisher run 38017125709 的 verify job 连续收到版本 JSON 路由 404,导致整体失败;随后项目 JSON、版本 JSON 和安装索引均列出真实 0.5.1 文件。完整缓存传播机制未证明,不将其猜测当根因。
安装可用性由项目已有的 Simple 安装索引表达,避免将新版本 JSON 路由可见性当成消费边界;使用官方 PEP 691 内容协商与哈希字段。不是跳过验证、直接改判成功或重复上传。CI 与 publisher 的质量检查同时锁定触发 commit 的完整 SHA,避免不同 job 读取移动 ref 而验证不同源代码。
改动类型
验证
合入后继续通过程序自身生成的下一补丁发布验证完整 Actions 链路;ClawHub 保持手动,不上传。
合规