From 9b6d6aff21d173f039b238f310fb87c887a472f6 Mon Sep 17 00:00:00 2001 From: "Teemu R." Date: Sun, 4 Oct 2026 20:26:26 +0200 Subject: [PATCH] Fix PyPI publishing for packages with metadata 2.5 (#1779) The 0.11.0 release failed to upload to PyPI as hatchling version used in the CI created metadata that was not accepted by pypi. This commit pins the versions for the release pipeline to avoid such surprises in the future. --- .github/build-constraints.txt | 2 ++ .github/workflows/publish.yml | 4 ++-- pyproject.toml | 2 +- 3 files changed, 5 insertions(+), 3 deletions(-) create mode 100644 .github/build-constraints.txt diff --git a/.github/build-constraints.txt b/.github/build-constraints.txt new file mode 100644 index 00000000..712e6925 --- /dev/null +++ b/.github/build-constraints.txt @@ -0,0 +1,2 @@ +# Pin the build backend for reproducible release builds. +hatchling==1.32.4 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index c4dff1ae..fc94377c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -29,8 +29,8 @@ jobs: - name: Build Packages id: build-packages shell: bash - run: uv build + run: uv build --build-constraints .github/build-constraints.txt - name: Publish Release on PyPI id: publish-release-on-pypi - uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 diff --git a/pyproject.toml b/pyproject.toml index 564dc872..8f901f1e 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -67,7 +67,7 @@ docs = [ ] [build-system] -requires = ["hatchling"] +requires = ["hatchling>=1.27"] build-backend = "hatchling.build" [tool.hatch.build.targets.sdist]