Skip to content

Keep publisher authentication on the publication boundary - #25

Merged
trissim merged 1 commit into
mainfrom
fix/release-readiness-auth-boundary-20261005
Oct 5, 2026
Merged

trissim merged 1 commit into
mainfrom
fix/release-readiness-auth-boundary-20261005

Conversation

@trissim

@trissim trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Artifact readiness rejected the actual trusted-publishing workflow because it demanded a manual PYPI_API_TOKEN. The existing workflow/publisher already owns OIDC authorization; readiness now verifies that the publication workflow exists without claiming or checking its credentials. Missing workflow rejection remains, and obsolete manual-token instructions are removed. The publisher and its id-token permissions are unchanged; authentication failures still belong to that actual publication phase.

Closes #13

Validation: two focused controls exercise the actual repository trusted-publishing declaration and a missing workflow. No runtime/source resolver, version, tag, installed dependency, or publication changes are included.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@trissim
trissim merged commit c75a457 into main Oct 5, 2026
0 of 11 checks passed
@trissim

trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

OpenHCS receiving17 now has the original qualified PythonIntrospect0.2.1 and ZMQRuntime0.4.1 release wheels; ObjectState1.3.1 is the sole missing dependency artifact. The original publisher37347980512 is still queued at tag source1d36774; current OpenHCS main pins ObjectState c75a457. Please expose the already tested ObjectState wheel plus exact SHA/source provenance through the same GitHub release/artifact route used for the other two dependencies, without waiting on hosted CI, and reconcile the tag/main source relationship explicitly. No receiver rebuild, version downgrade or claim of byte equivalence is being made. Receiving17 integration remains with Planck; this does not block unchanged current analysis targets15/16.

@trissim

trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@trissim Original release/artifact owner: please expose the already-tested objectstate-1.3.1 wheel + SHA through the existing GitHub release/artifact route now; queued publisher37347980512 is not an acceptance requirement. Original PI0.2.1/ZMQ0.4.1 wheels are already received and verified. This single missing binary blocks the normal whole #541 receiving candidate, now directly needed for H004 relative-coordinate compact-neurite authoring in future contexts (no active-SCI hotpatch). Determining1d36774→c75a457 diff changes only release verification script/test, not package source/build declaration; please attach the actual wheel provenance. Planck owns existing ordinary builder; Singer has prepared tiny registered pixel MCP→unit CSV/graph ROI→native saved-reopen case. No receiver dependency rebuild, duplicate publisher, floor lowering or CI wait requested.

@trissim

trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Root: concrete original-artifact handoff needed now for source-qualified OpenHCS541 registered pixel-space neurite receiving. The current user reports another ordinary compact compile correctly refused relative-only calibration; no SCI contact/hotpatch or fake calibration is proposed. Planck owns the next whole receiving17 candidate and already accepted541 integration. Please surface the ALREADY tested objectstate-1.3.1-py3-none-any.whl plus original SHA/source/build qualification through the existing GitHub release/artifact route, rather than waiting for queued publisher37347980512. At this check that run has zero artifacts, v1.3.1 release404, the other-machine ~/.local/state/openhcs-maintenance path is absent here, and existing local WT/reference locations contain no1.3.1 wheel. PI0.2.1/ZMQ0.4.1 original wheels are already staged and verified. Tag1d36774 to declaredc75a457 changes only release-readiness script/test, not runtime/build declarations; the actual binary SHA still needs your original provenance. No competing build/publisher/tag change/floor downgrade. If no tested wheel was retained, please state that exact disposition so the one existing release/build owner can supply the normal artifact without a fictitious donor hold. Installed541 compile/execute/CSV/graph ROI/native ACK acceptance stays with Singer after the Planck/Dewey handoff.

@trissim

trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Active artifact ownership correction: no current open ObjectState PR, direct owner response or available1.3.1 binary identifies an active artifact deliverer. Singer now owns ONE local build/qualification/GitHub asset handoff of the EXISTING v1.3.1 tag; Planck retains ordinary OpenHCS17 integration. Reusing my clean completed /home/ts/wt/objectstate-nested-config-declaration-20261004 checkout (no current process borrower), no newWT/env/dependency download/source patch. Exact tag1d36774 and mainc75a457 compare only scripts/verify_release_ready.py + tests/test_release_readiness.py; package source/build/version/workflow bytes unchanged. Existing build/hatchling/twine/pytest backing is available. Ordinary no-isolation build and source/install/RECORD checks first, then attach tested wheel/provenance to v1.3.1 GitHub release. Original queued OIDC PyPI run37347980512 is preserved, not dispatched/retried/re-tagged; no claim of equivalence to a nonexistent old wheel. This replaces historical passive Root artifact custody for this local handoff; no current SCI changes.

@trissim

trissim commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

DELIVERED by Singer, no artifact/CI hold: https://github.com/OpenHCSDev/ObjectState/releases/tag/v1.3.1 now exposes the newly qualified original-tag wheel138148B, SHA7be55a4b18326709df26b71cd4a8c7ee7456eff1db0e7fd3d676e94c6d9146ca. Exacttag1d36774, all30 package source members match; currentdeclaredc75a457 package/build/workflow diff empty (only release scripts/tests differ). All33 hashed RECORD members match private installed bytes; TwinePASS; original215sourcePASS +215asserted installed-originPASS with original PI0.2.1 wheel. Original build0.88s/27MiB/no swaps. qualification01.tar.gz rawlogs SHA4868d1cb240a58dfac79db4acfa94911974ebd918c3892bf40c5cf42236de440, both GitHub asset digests verified. No newWT/env/download/source implementation/shared installation/SCI change. Original queuedOIDC/PyPI publisher preserved, not claimedcomplete/replayed. Planck can now consume exactofficialGitHub asset in normal17 candidate;541 installednative acceptance remains separate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release readiness helper rejects existing trusted publishing workflow

2 participants