Commit b5c2871
ci: address review — SHA-pin release actions + fail-loud dev-version stamp
Two medium findings from the PR review:
- [security] The wheel/sdist now published to PUBLIC PyPI is built in the
release job, which pulled actions via mutable tags (setup-uv@v4,
docker/{setup-buildx,login,build-push}@vn). A repointed tag / upstream
takeover would reach every `pip install coder-eval` user, in a job that
also holds RELEASE_APP_PRIVATE_KEY and the Azure PAT. Pin all four to
full commit SHAs (setup-uv now matches publish-testpypi.yml).
- [resilience] The TestPyPI dev-version stamp used re.sub, which returns
the text unchanged (rc=0) on a version-line format drift, silently
publishing the base version -> TestPyPI collision masked by
skip-existing, so the dry run passes green having validated nothing.
Switch to re.subn and SystemExit when the match count != 1.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 28e3ac4 commit b5c2871
2 files changed
Lines changed: 11 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
77 | 83 | | |
78 | 84 | | |
79 | 85 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
82 | | - | |
| 82 | + | |
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
164 | | - | |
| 164 | + | |
165 | 165 | | |
166 | 166 | | |
167 | 167 | | |
168 | | - | |
| 168 | + | |
169 | 169 | | |
170 | 170 | | |
171 | 171 | | |
172 | 172 | | |
173 | 173 | | |
174 | 174 | | |
175 | 175 | | |
176 | | - | |
| 176 | + | |
177 | 177 | | |
178 | 178 | | |
179 | 179 | | |
| |||
0 commit comments