Release pipeline: never draft after a failed PyPI publish, verify the index both ways, keep finals re-runnable - #15
Merged
Conversation
… index both ways, keep finals re-runnable A second review round found that github-release accepted a skipped smoke-pypi unconditionally, and a skipped smoke-pypi also means publish-pypi failed or a reviewer rejected the deployment: a final whose PyPI upload never happened would still get a draft release for a human to publish. The job now requires smoke-pypi to have succeeded whenever PyPI publication was expected. The version policy treated the newest published version as a violation, which blocked a fresh dispatch on a tag after its PyPI upload (the only recovery for a failure in smoke-pypi or github-release besides re-running failed jobs). It is now a warning: tags never move and verify-index-files proves the served bytes, so a re-run is safe. verify-index-files also fails when the index serves files this run did not build or serves yanked files, retries transient registry errors instead of failing on the first 503, and explains that a fresh rebuild with a different uv version changes the wheel's Generator stamp. draft-release refuses to touch a tag that any published release owns, so gh's tag lookup can no longer resolve to a published release while the guard looked at a draft. Artifacts per lane get overwrite: true and the junit names carry the lane. Tag parsing anchors at end of string, rejects '..' plugin names, and GITHUB_OUTPUT values refuse line breaks. Dead paginated-JSON helper removed; tests cover every new branch and no longer serialize a whole job to search for a string.
This was referenced Sep 10, 2026
Member
|
Can we update the AGENTS.md to use the full command from the testing section: |
brianstrauch
approved these changes
Sep 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Second review round on the release pipeline, split out because #13 merged while it was in progress. Same scope (#12), all tooling-only.
Changes
github-releaseaccepted a skippedsmoke-pypiunconditionally, but a skippedsmoke-pypialso meanspublish-pypifailed or apypireviewer rejected the deployment: a final whose PyPI upload never happened still got a draft release for a human to publish. The job now requiressmoke-pypito have succeeded whenever PyPI publication was expected.smoke-pypiorgithub-releasebesides re-running failed jobs). It is now a warning: tags never move andverify-index-filesproves the served bytes.verify-index-filesboth ways. It also fails when the index serves files this run did not build (a foreign platform wheel would win resolution over ours) or serves yanked files; transient registry errors are retried instead of failing on the first 503; the mismatch message explains that a fresh rebuild with a different uv version changes the wheel'sGeneratorstamp and points at "Re-run failed jobs".gh release upload <tag>can never resolve to a published release while the guard looked at a draft.overwrite: true(a re-run of the test job replaces the artifact instead of leaving two behind) and the junit artifact names carry the dependency lane (ci.ymlruns two lanes for one plugin in one run)...plugin names;GITHUB_OUTPUTvalues refuse line breaks; the dead paginated-JSON helper is gone; the workflow tests assert on step env values instead of serialising a whole job to search for a string.taginput from a branch (skip-publishis for dispatching on an existing tag ref); recovery describes "Re-run failed jobs" vs a fresh dispatch and the uv-version caveat.Testing
uv run --project scripts --locked pytest scripts/tests -q: 86 passed (new: no draft unlesssmoke-pypisucceeded when expected; newest-published re-run warning while final gates still apply; foreign files, yanked files and transient errors inverify-index-files;..and line-break rejection in tag parsing and outputs;overwrite: trueand lane-qualified junit names).scripts/ci/check_conventions.py: OK