Recover immutable release publication #1
release-recovery.yml
on: workflow_dispatch
Verify the authorized immutable release recovery
2s
Run the protected publication recovery
/
Verify and build the immutable default-branch release
53s
Run the protected publication recovery
/
Verify the exact release commit against CometAPI
30s
Run the protected publication recovery
/
Publish verified artifacts with PyPI OIDC
18s
Run the protected publication recovery
/
Verify the public registry artifact
Deployment protection rules
Reviewers, timers, and other rules protecting deployments in this run
| Event | Environments |
|---|---|
|
tensornull
approved
|
pypi |
Annotations
1 warning and 1 notice
|
Run the protected publication recovery / Publish verified artifacts with PyPI OIDC
Potential workflow misconfiguration:
The claims in this token suggest that the calling workflow is a reusable workflow.
In particular, this action was initiated by:
cometapi-dev/cometapi-python/.github/workflows/publish.yml@refs/heads/main
Whereas its parent workflow is:
cometapi-dev/cometapi-python/.github/workflows/release-recovery.yml@refs/heads/main
Reusable workflows are **not currently supported** by PyPI's Trusted Publishing
functionality, and are subject to breakage. Users are **strongly encouraged**
to avoid using reusable workflows for Trusted Publishing until support
becomes official. Please, do not report bugs if this breaks.
For more information, see:
* https://docs.pypi.org/trusted-publishers/troubleshooting/#reusable-workflows-on-github
* https://github.com/pypa/gh-action-pypi-publish/issues/166 — subscribe to
this issue to watch the progress and learn when reusable workflows become
supported officially
|
|
Run the protected publication recovery / Publish verified artifacts with PyPI OIDC
Generating and uploading digital attestations
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
release-0.1.0
Expired
|
85.1 KB |
sha256:4d702bc5e2d21718558571f043adc1711b129e263d63480f5c09108e8ca35ca1
|
|