fix(release): verify script installs only from the given index, wheel-only

Review findings:
- UV_FIND_LINKS / extra-index env vars or a uv.toml could redirect the
  install to a local build and false-pass the gate; now --no-config on
  every uv call and refuse to run when an index-redirecting var is set
- an sdist fallback would build with backends fetched from TestPyPI;
  install the package with --only-binary :all:
- show the package install (no -q) so the log records what was installed
- changelog: note the removed [dev] extra

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
golem
2026-10-05 21:40:29 -06:00
co-authored by Claude Opus 5.5
parent d0e78f53fc
commit 63af95a769
2 changed files with 20 additions and 4 deletions
+2
View File
@@ -11,6 +11,8 @@ Hotfix. In 0.2.2, `import app_skellington` raised
* Tested on Linux, CPython 3.8–3.14 (Gitea CI). Each version builds the wheel
and sdist, installs them and smoke-tests the import.
* Tooling: ruff replaces black/isort/flake8; uv with a committed lockfile.
* Removed the `[dev]` extra: `pip install app_skellington[dev]` no longer
installs dev tools. Contributors use `uv sync` (a PEP 735 dependency group).
* Metadata: license classifier corrected to MIT-0; Python version classifiers
added; "OS Independent" replaced by Linux (Windows and macOS untested).
* README: the debug variable is `APPSKELLINGTON_DEBUG`.
+18 -4
View File
@@ -12,17 +12,31 @@ index="${2:-https://test.pypi.org/simple/}"
here="$(cd "$(dirname "$0")" && pwd)"
pythons=(3.8 3.9 3.10 3.11 3.12 3.13 3.14)
# The package must come from $index and nowhere else. Otherwise a local
# build could pass for the published release. --no-config ignores
# uv.toml/pyproject settings; these variables would still redirect, so refuse.
for var in UV_INDEX UV_INDEX_URL UV_DEFAULT_INDEX UV_EXTRA_INDEX_URL \
UV_FIND_LINKS UV_INDEX_STRATEGY UV_NO_INDEX PIP_INDEX_URL \
PIP_EXTRA_INDEX_URL PIP_FIND_LINKS; do
if [ -n "${!var:-}" ]; then
echo "refusing: $var is set and could redirect the install away from $index" >&2
exit 2
fi
done
work="$(mktemp -d)"
trap 'rm -rf "$work"' EXIT
for py in "${pythons[@]}"; do
venv="$work/$py"
uv venv -q --python "$py" "$venv"
uv pip install -q --python "$venv" --no-cache --no-deps \
--index-url "$index" "app_skellington==$version"
uv venv -q --no-config --python "$py" "$venv"
# Wheel only: an sdist fallback would fetch its build backend from $index
# (TestPyPI). Not quiet, so the log shows what was installed.
uv pip install --no-config --python "$venv" --no-cache --no-deps \
--only-binary :all: --index-url "$index" "app_skellington==$version"
"$venv/bin/python" -c 'import importlib.metadata as m; print("\n".join(m.requires("app_skellington") or []))' \
> "$work/requirements.txt"
uv pip install -q --python "$venv" -r "$work/requirements.txt"
uv pip install -q --no-config --python "$venv" -r "$work/requirements.txt"
(cd / && "$venv/bin/python" "$here/smoke_import.py" "$version")
done