fix(release): verify script installs only from the given index, wheel-only
Review findings: - UV_FIND_LINKS / extra-index env vars or a uv.toml could redirect the install to a local build and false-pass the gate; now --no-config on every uv call and refuse to run when an index-redirecting var is set - an sdist fallback would build with backends fetched from TestPyPI; install the package with --only-binary :all: - show the package install (no -q) so the log records what was installed - changelog: note the removed [dev] extra Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -11,6 +11,8 @@ Hotfix. In 0.2.2, `import app_skellington` raised
|
||||
* Tested on Linux, CPython 3.8–3.14 (Gitea CI). Each version builds the wheel
|
||||
and sdist, installs them and smoke-tests the import.
|
||||
* Tooling: ruff replaces black/isort/flake8; uv with a committed lockfile.
|
||||
* Removed the `[dev]` extra: `pip install app_skellington[dev]` no longer
|
||||
installs dev tools. Contributors use `uv sync` (a PEP 735 dependency group).
|
||||
* Metadata: license classifier corrected to MIT-0; Python version classifiers
|
||||
added; "OS Independent" replaced by Linux (Windows and macOS untested).
|
||||
* README: the debug variable is `APPSKELLINGTON_DEBUG`.
|
||||
|
||||
@@ -12,17 +12,31 @@ index="${2:-https://test.pypi.org/simple/}"
|
||||
here="$(cd "$(dirname "$0")" && pwd)"
|
||||
pythons=(3.8 3.9 3.10 3.11 3.12 3.13 3.14)
|
||||
|
||||
# The package must come from $index and nowhere else. Otherwise a local
|
||||
# build could pass for the published release. --no-config ignores
|
||||
# uv.toml/pyproject settings; these variables would still redirect, so refuse.
|
||||
for var in UV_INDEX UV_INDEX_URL UV_DEFAULT_INDEX UV_EXTRA_INDEX_URL \
|
||||
UV_FIND_LINKS UV_INDEX_STRATEGY UV_NO_INDEX PIP_INDEX_URL \
|
||||
PIP_EXTRA_INDEX_URL PIP_FIND_LINKS; do
|
||||
if [ -n "${!var:-}" ]; then
|
||||
echo "refusing: $var is set and could redirect the install away from $index" >&2
|
||||
exit 2
|
||||
fi
|
||||
done
|
||||
|
||||
work="$(mktemp -d)"
|
||||
trap 'rm -rf "$work"' EXIT
|
||||
|
||||
for py in "${pythons[@]}"; do
|
||||
venv="$work/$py"
|
||||
uv venv -q --python "$py" "$venv"
|
||||
uv pip install -q --python "$venv" --no-cache --no-deps \
|
||||
--index-url "$index" "app_skellington==$version"
|
||||
uv venv -q --no-config --python "$py" "$venv"
|
||||
# Wheel only: an sdist fallback would fetch its build backend from $index
|
||||
# (TestPyPI). Not quiet, so the log shows what was installed.
|
||||
uv pip install --no-config --python "$venv" --no-cache --no-deps \
|
||||
--only-binary :all: --index-url "$index" "app_skellington==$version"
|
||||
"$venv/bin/python" -c 'import importlib.metadata as m; print("\n".join(m.requires("app_skellington") or []))' \
|
||||
> "$work/requirements.txt"
|
||||
uv pip install -q --python "$venv" -r "$work/requirements.txt"
|
||||
uv pip install -q --no-config --python "$venv" -r "$work/requirements.txt"
|
||||
(cd / && "$venv/bin/python" "$here/smoke_import.py" "$version")
|
||||
done
|
||||
|
||||
|
||||
Reference in New Issue
Block a user