Commit 402e27d
authored
fix(ci): make a failed publish retryable, and unpin the stale twine (#63)
* fix(ci): make a failed publish retryable, and unpin the stale twine
v0.11.0 was tagged and its GitHub Release created, but the PyPI upload failed:
Checking dist/hotdata_framework-0.11.0-py3-none-any.whl:
ERROR InvalidDistribution: Invalid distribution metadata:
'2.5' is not a valid metadata version
Nothing to do with the code. gh-action-pypi-publish was pinned at v1.13.0
(Sept 2025), whose bundled twine predates `Metadata-Version: 2.5`, which current
hatchling emits. Bumped to v1.14.2.
Note the build job's own `twine check --strict` PASSED, because it
pip-installs a current twine. So the incompatibility was invisible until upload,
by which point the tag was already public -- the check that exists to catch bad
metadata cannot catch this class at all.
RETRYABILITY IS THE REAL FIX. Both workflows triggered only on tag push, so a
publish that failed for reasons unrelated to the code left two bad options:
delete and re-push the tag, or burn a version number on a CI fix. Neither is a
reasonable answer to "the upload failed, run it again". Both now accept a
workflow_dispatch with a tag input, checkout that ref, and derive the version
from it.
release.yml gets the same treatment for a second reason: RELEASING.md already
documents the recovery command
gh workflow run "GitHub Release" --ref main -f tag=vX.Y.Z
and the trigger it needs was never there, so that documented path has always
failed. This makes the doc true.
Verified both files parse with triggers ['push', 'workflow_dispatch'] and a
`tag` input, and no GITHUB_REF_NAME references remain in either.
* fix(ci): watch action pins, and stop dispatch from demoting a newer release
Three review findings, all confirmed before acting.
Dependabot had no github-actions ecosystem at all -- only a uv entry narrowed to
one dependency -- which is how gh-action-pypi-publish sat at v1.13.0 until its
bundled twine broke a release at upload. Added, with no allow filter, since the
point is to see every stale pin rather than a chosen one. Fixes the class, not
just the instance.
make_latest was unconditional. On the push trigger the tag is always the newest
version so that is right, but a dispatch repairs a Release for a tag that
already exists, by which time a newer version may have shipped -- re-running for
an older tag would silently demote the newer one and point /releases/latest at
it. Now gated on the push event.
And my comment cited a RELEASING.md recovery section that is not in this repo.
It is in sdk-python's RELEASING.md; I read that one earlier and attributed it
here. So the trigger was adding a capability documented nowhere, not making a
doc true. Added the section for real, including the bit worth stating outright:
--ref main selects the workflow definition while the tag input selects what gets
built, which reads like a contradiction until you know they differ on purpose.
* fix(ci): make_latest legacy, not a gate on the event
The gate was backwards for the case the dispatch will mostly see. make_latest is
not "set latest / leave alone" -- false is an explicit instruction that a release
is NOT the latest. release.yml's dispatch exists to repair a Release that failed
on the push run, where the tag IS the newest version, so gating on the event
passed false exactly there and left /releases/latest on the previous version.
legacy covers both directions without the workflow having to know which case it
is in: GitHub picks by tag date and semver, so repairing the newest tag marks it
latest and repairing an older one leaves the newer release alone.
* docs(releasing): scope what --ref main actually picks up
"any fix landed since the tag" was too broad. Both workflows check out
ref: ${{ inputs.tag || github.ref_name }}, so only the workflow YAML comes from
main -- everything it runs comes from the tag, including
scripts/extract-changelog.py. That is the right design, but the loose wording
invites the opposite conclusion for the exact failure this section covers: if
that script is what broke, a dispatch re-run does not pick up its fix.1 parent 54b33f0 commit 402e27d
4 files changed
Lines changed: 80 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
7 | 18 | | |
8 | 19 | | |
9 | | - | |
| 20 | + | |
10 | 21 | | |
11 | 22 | | |
12 | 23 | | |
| |||
16 | 27 | | |
17 | 28 | | |
18 | 29 | | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
19 | 33 | | |
20 | 34 | | |
| 35 | + | |
| 36 | + | |
21 | 37 | | |
22 | 38 | | |
23 | 39 | | |
| |||
28 | 44 | | |
29 | 45 | | |
30 | 46 | | |
31 | | - | |
32 | | - | |
| 47 | + | |
| 48 | + | |
33 | 49 | | |
34 | 50 | | |
35 | | - | |
| 51 | + | |
36 | 52 | | |
37 | 53 | | |
38 | 54 | | |
| |||
65 | 81 | | |
66 | 82 | | |
67 | 83 | | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
68 | 89 | | |
69 | | - | |
| 90 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
7 | 16 | | |
8 | 17 | | |
9 | 18 | | |
| |||
12 | 21 | | |
13 | 22 | | |
14 | 23 | | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
15 | 27 | | |
16 | 28 | | |
| 29 | + | |
| 30 | + | |
17 | 31 | | |
18 | 32 | | |
19 | 33 | | |
| |||
23 | 37 | | |
24 | 38 | | |
25 | 39 | | |
26 | | - | |
| 40 | + | |
27 | 41 | | |
28 | 42 | | |
29 | 43 | | |
30 | 44 | | |
31 | 45 | | |
32 | 46 | | |
33 | 47 | | |
34 | | - | |
| 48 | + | |
35 | 49 | | |
36 | 50 | | |
37 | 51 | | |
| |||
47 | 61 | | |
48 | 62 | | |
49 | 63 | | |
50 | | - | |
| 64 | + | |
51 | 65 | | |
52 | 66 | | |
53 | 67 | | |
54 | | - | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
37 | 58 | | |
38 | 59 | | |
39 | 60 | | |
| |||
0 commit comments