Skip to content

fix: repair packaging and secure reproducible release tooling - #59

Merged
John Xing (johnxing-amigo) merged 2 commits into
mainfrom
maintenance/public-repo-quality
Sep 8, 2026
Merged

John Xing (johnxing-amigo) merged 2 commits into
mainfrom
maintenance/public-repo-quality

Conversation

@johnxing-amigo

@johnxing-amigo John Xing (johnxing-amigo) commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

The wheel advertised development commands whose scripts were excluded from the package, code generation embedded a changing timestamp, the lock contained known dependency advisories, and release notes interpolated commit text into shell code. Remove the broken wheel entry points, document checkout-local commands, refresh vulnerable runtime and development dependencies, make generation repeatable, and pass release-note and summary text through environment variables. Release inputs are quoted data, version types are validated, and the reused fixture test job no longer inherits release secrets. Validate refreshed models before publication and correct ownership and contributor guidance.

Validation: 200 unit tests passed (8 skipped; 40 provisioned integration tests deselected), 88.46% coverage, ruff, mypy, strict MkDocs, and wheel/sdist builds passed. The wheel contains no broken entry points or bytecode. Two consecutive generations produced the same SHA-256, with no model-body changes. pip-audit reports zero known vulnerabilities in the resolved runtime, dev, and docs dependencies. A shell-metacharacter fixture preserved literal commit text without executing it. actionlint passed with the existing Blacksmith runner label allowed.

Release impact: patch 2.0.1. Development dependencies now require pytest 9 and pytest-asyncio 1; the SDK remains Python 3.11+ and Classic-only. Existing informational integration checks need a working provisioned environment and are not counted as validation here.

@johnxing-amigo
John Xing (johnxing-amigo) merged commit 04bad6f into main Sep 8, 2026
7 of 8 checks passed
@johnxing-amigo
John Xing (johnxing-amigo) deleted the maintenance/public-repo-quality branch September 8, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant