fix: repair packaging and secure reproducible release tooling - #59
Merged
Merged
Conversation
John Xing (johnxing-amigo)
deleted the
maintenance/public-repo-quality
branch
September 8, 2026 02:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The wheel advertised development commands whose scripts were excluded from the package, code generation embedded a changing timestamp, the lock contained known dependency advisories, and release notes interpolated commit text into shell code. Remove the broken wheel entry points, document checkout-local commands, refresh vulnerable runtime and development dependencies, make generation repeatable, and pass release-note and summary text through environment variables. Release inputs are quoted data, version types are validated, and the reused fixture test job no longer inherits release secrets. Validate refreshed models before publication and correct ownership and contributor guidance.
Validation: 200 unit tests passed (8 skipped; 40 provisioned integration tests deselected), 88.46% coverage, ruff, mypy, strict MkDocs, and wheel/sdist builds passed. The wheel contains no broken entry points or bytecode. Two consecutive generations produced the same SHA-256, with no model-body changes. pip-audit reports zero known vulnerabilities in the resolved runtime, dev, and docs dependencies. A shell-metacharacter fixture preserved literal commit text without executing it. actionlint passed with the existing Blacksmith runner label allowed.
Release impact: patch 2.0.1. Development dependencies now require pytest 9 and pytest-asyncio 1; the SDK remains Python 3.11+ and Classic-only. Existing informational integration checks need a working provisioned environment and are not counted as validation here.