From 9210b1488d7f25845ca001837e585baebf947c6e Mon Sep 17 00:00:00 2001 From: Rand Lee Date: Thu, 24 Sep 2026 08:09:36 -0700 Subject: [PATCH] release(1.6.1): check out the dispatch ref in the PyPI publish workflow Publish PyPI run 36017176129 checked out the immutable tag v1.6.1 and ran that commit's release_artifacts.py, reproducing the sdist rejection that #1592 fixed on main. The workflow never builds from source; the checkout only supplies the verify tooling and the manifest, so it must come from the dispatched commit (sc-publish#76, the v1.4.4 fix the phase-bc re-render dropped). Release assets are still downloaded by tag. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/pypi-publish.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/pypi-publish.yml b/.github/workflows/pypi-publish.yml index 573bb194b..4ac46b3f2 100644 --- a/.github/workflows/pypi-publish.yml +++ b/.github/workflows/pypi-publish.yml @@ -35,9 +35,10 @@ jobs: pypi_config: ${{ steps.config.outputs.config }} python_upload_tool: ${{ steps.config.outputs.python_upload_tool }} steps: + # Check out the dispatch ref, not the immutable tag: this workflow only + # downloads published release assets, so the checkout supplies tooling + # and the manifest (sc-publish#76). - uses: actions/checkout@v5 - with: - ref: ${{ inputs.tag }} - uses: ./.github/actions/verify-published-release with: release_tag: ${{ inputs.tag }} @@ -57,9 +58,10 @@ jobs: runs-on: ubuntu-latest environment: ${{ inputs.target == 'production' && 'pypi' || 'testpypi' }} steps: + # Check out the dispatch ref, not the immutable tag: this workflow only + # downloads published release assets, so the checkout supplies tooling + # and the manifest (sc-publish#76). - uses: actions/checkout@v5 - with: - ref: ${{ inputs.tag }} - name: Download Python assets from the published GitHub Release shell: bash env: