Repository navigation
Publish Python packages with PyPI Trusted Publishing - #519
Jaydeep869 wants to merge 1 commit into
Conversation
4bd4e62 to
74897a2
Compare
mlieberman85
left a comment
There was a problem hiding this comment.
Thanks, this is a solid migration, and it also fixes the smoke matrix (darnit -> darnit-core) and aligns release.yml with the smoke workflow's existing TestPyPI expectation for rc tags.
Two things before merge:
- rc container dependency confusion. With
--index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/, pip picks the highest version across both indexes, and anyone can register any name on TestPyPI. A squattedmcp,pydantic, ordarnit-*release on TestPyPI with a higher version would be installed into the:rcimage we sign and push. Could the image build install the darnit wheels from this run'sbuildartifacts (for examplepip install --no-index --find-links ./dist darnit-mcp==$VERSIONfor the darnit packages, then dependencies from pypi.org only), or at least install the darnit packages from TestPyPI with--no-depsand resolve dependencies from PyPI alone? - rc release notes. The GitHub Release body still says
pip install darnit-mcp==${VERSION}(PyPI). For rc tags that version now only exists on TestPyPI, so the install instructions should switch to the TestPyPI form, asdocs/install/pypi.mddoes.
Smaller:
attestations: writeisn't needed for PyPI's PEP 740 attestations, which use the OIDC token (id-token: write). Could you drop it for least privilege?- Please add the "AI assistance" section from the PR template (and an
Assisted-by:trailer if AI was used).
@Marc-cn and I (and anyone else who's interested) will handle setting up the Trusted Publishers and the release environment on the PyPI/TestPyPI side.
|
I can take the PyPI/TestPyPI side, Trusted Publishers plus the Two questions before I set it up: @mlieberman85, do you already own these five names on PyPI and TestPyPI, or do some need registering? Trusted Publishing needs either an existing project or a pending publisher, and the names must match exactly. Also: do you want me added as owner on the PyPI orgor would you rather configure and I verify? @Jaydeep869 |
|
@Marc-cn Thanks for the review. On the darnit-csl i followed the existing public package list, so leaving out darnit-csl was not intentional. Since it is an installable plugin and its README already documents pip install darnit-csl, I think it should be included as the sixth published package. I will update the workflow and docs for it. For the container image, I will keep it out unless we decide the MCP image should include optional plugins too. |
Signed-off-by: jaydeep869 <jaydeeppokhariya2106@gmail.com> Assisted-by: OpenAI Codex
74897a2 to
f8de207
Compare
|
Thanks Mike and Marco. I pushed updates for the review points: the container now installs Darnit packages from this run's built wheel artifacts and uses PyPI only for external dependencies, rc release notes now show the TestPyPI install command, publish jobs no longer request attestations: write, and the PR now includes the AI assistance section plus an Assisted-by trailer. I also added darnit-csl as the sixth public package and included it in publish docs and smoke tests. |
|
Checked the updates, container installs the darnit wheels from this run's So five Trusted Publisher configs on existing PyPI projects, plus seven pending publishers (six on TestPyPI, one for darnit-csl on PyPI). The existing five are Kusari's 0.1.0 from before the org move, "darnit-core"'s metadata still lists "kusari-oss/darnit" as homepage and repository. The publisher config needs "darnitdevorg/darnit2and the project URLs are worth refreshing on the next release. @mlieberman85, the five existing PyPI projects need an owner to add the publisher. Can you add me as owner or would you rather configure those five while I do the seven pending ones? Either works. Also yours to clear the requested-changes review. |
mlieberman85
left a comment
There was a problem hiding this comment.
Thanks for reworking this; the earlier review points are addressed. We want to land Trusted Publishing, and #558 already moves the publish jobs into the protected release environment. Before merge:
container-edge.ymlbuilds the same Dockerfile withoutdist/, soCOPY dist /tmp/distwould break every push tomain. It needs a source-install path, ordistbuilt in that workflow.- Drop
--prefrom the Dockerfile; it pulls prerelease dependencies into stable images. darnit-cslis still 0.1.0, which fails the release preflight. Either bump it or leave it out of the public list for now; we'll decide which.- Update the local-build instructions in
packaging/container/README.md, and delete or alignpublish.yml. - Rebase onto #558 once it merges.
Drafted with Claude Code; reviewed and posted by me.
Addresses #228
Summary
darnit-cslTesting
ruff check .pytest tests/packaging/test_wheel_install_config.py tests/darnit_reproducibility/test_container_pinning.py -q(22 passed)git diff --checkThe broader test run previously reached 3074 passed, with existing parity harness timeouts and the product source guard failure unrelated to these packaging-only changes.
AI assistance
@mlieberman85 and @Marc-cn, could you please take another look, especially at the Trusted Publisher setup and public package list?