Skip to content

Wait for registry propagation without republishing accepted packages - #16

Merged
cloneismin merged 1 commit into
mainfrom
codex/sdk-provenance-propagation-20261004
Oct 4, 2026
Merged

cloneismin merged 1 commit into
mainfrom
codex/sdk-provenance-propagation-20261004

Conversation

@cloneismin

Copy link
Copy Markdown
Contributor

npm and PyPI accepted the 0.7.1/0.2.1 uploads, but verification ran before their public services had finished propagating. npm installation succeeded before its attestation endpoint returned 200; PyPI metadata was available before its simple index listed the wheel. Both first verification runs therefore failed after successful publication.

Wait at most 20 attempts for npm attestation E404 and PyPI version/index availability. Other signature, hash, HTTP and parsing failures fail immediately. Check that PyPI metadata and the install index expose the same wheel hash as the tested release. Add a PyPI verification-only input so a successful upload never needs to be repeated.

Validation: 12 script tests passed, including transient recovery, integrity failures and bounded failure for both registries; YAML parsing and shell syntax passed. npm verification-only run 37208694225 passed, and a fresh anonymous PyPI installation/import succeeded after index propagation.

@cloneismin
cloneismin merged commit 336f967 into main Oct 4, 2026
3 checks passed
@cloneismin
cloneismin deleted the codex/sdk-provenance-propagation-20261004 branch October 4, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant