-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add warning about pinned gh-action-pypi-publish in publish-pypi #78
Add warning about pinned gh-action-pypi-publish in publish-pypi #78
Conversation
Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.9.0 to 1.12.4. - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@v1.9.0...v1.12.4) --- updated-dependencies: - dependency-name: pypa/gh-action-pypi-publish dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
@IgorTatarnikov I've assigned this one to you following #77 |
Also cc @lochhh, is this something we want/need? |
I'll use this PR to change the script to have our new standard (brainglobe/brainglobe-atlasapi#456) |
On second thought, this action should be deprecated as it is no longer be functional due to upstream changes in pypa/gh-action-pypi-publish@release/v1 |
Since on gh-action-pypi-publish's readme they mentioned:
We could still keep this action, but I added a warning in the readme |
In that case should we pin it to the last working version, and leave it with a warning? |
yup good idea! |
@IgorTatarnikov I'm not sure what the last working version is, as the note was only added in v1.8.12 |
This was based on empirical testing, when the upload action broke a couple of weeks ago we reverted to this version and it still worked. I'm comfortable pinning it to an even earlier version! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think it's good to go!
Bumps pypa/gh-action-pypi-publish from 1.9.0 to 1.12.4.
Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
... (truncated)
Commits
76f52bc
Merge pull request #329 from webknjaz/maintenance/runtime-lockfile-24-02-202572de13b
📌 Mass-upgrade transitive dependency pins1995f2e
Merge pull request #327 from webknjaz/maintenance/twine-6.1-pep63929f40bd
📦 Enable metadata 2.4 support in Twine10df67d
📦 Enable support for PEP 639 metadatae0449d2
🧪 Integrate a unifiedalls-green
GHA statuscebc64f
🧪 Bump setuptools in smoke test to v75.8.0da900af
🧪 Run smoke tests against Ubuntu 24 and 228cafb5c
💰 Sync the funding config916e576
Merge pull request #315 from webknjaz/refactoring/attestations-exist-bundleDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)