Skip to content

ci: Python releases pass the same gate as npm releases: main's checks on the tagged commit - #861

Merged
irparent merged 1 commit into
mainfrom
ci/pypi-requires-main-checks
Oct 6, 2026
Merged

irparent merged 1 commit into
mainfrom
ci/pypi-requires-main-checks

Conversation

@irparent

@irparent irparent commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Python releases now pass the same gate as npm releases: a py-v* tag publishes to PyPI only when the commit is on main and main's required checks passed on it, read by scripts/ci/require-checks-passed.mjs (the build job gains checks: read). A tag pushed while those runs are still going waits for them; one that failed stops the publish before anything is uploaded.

The step runs only for a py-v* tag; pull requests build the package exactly as before. tests/package-inventory.test.ts holds the step in place.

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
website Ignored Ignored Oct 6, 2026 8:30pm UTC

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
a20f8a60e27a92f7256845d40d1de564 failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent irparent changed the title ci: a PyPI release requires main's checks on the tagged commit, as the npm release does ci: Python releases pass the same gate as npm releases: main's checks on the tagged commit Oct 6, 2026
@irparent
irparent merged commit 4f316ae into main Oct 6, 2026
73 checks passed
@irparent
irparent deleted the ci/pypi-requires-main-checks branch October 6, 2026 20:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant