fix(ci): validate release source before building distributions - #5220
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsBlocking findings (1)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1e73b44c42
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed 1e73b44. The existing P2 about stale lockfiles remains actionable after an independent source check. Please use UV_LOCKED=1 or validate uv lock --check before the frozen matrix. The provenance validator checks commit/tag/version, and normal CI also uses frozen installs, so neither establishes that this release manifest matches the dependencies being tested. This is the same existing finding.
The Python 3.10–3.14 test loop, typecheck ordering, failure propagation, publisher isolation and artifact-ID handoff otherwise look sound. The shell regression exercises both intermediate test and typecheck failures. All 22 exact-head hosted checks passed. Source-only review with an independent workflow pass; no repository tests were run locally.
The frozen-versus-locked behavior is documented in uv locking and syncing.
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 20271c1b89
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
Summary
This pull request restores tests and type checks against the exact release source before PyPI publishing. The full test suite runs on Python 3.10–3.14 with locked dependencies, followed by type checking, before building or uploading distributions. Stale lockfiles fail validation instead of allowing tests to run against outdated dependencies. Checks run in a separate read-only job. After they pass, the build job independently checks out and validates the same release SHA on a fresh runner, so test-side filesystem, process, or environment changes cannot affect the distributions. Failed checks stop publication while preserving release provenance validation, environment approval, and the artifact-ID handoff to the isolated publisher.
Test plan
Issue number
N/A
Checks
.agents/skills/code-change-verification/scripts/run.sh/reviewbefore submitting this PRThe repository's required independent implementation review was completed by two reviewers; the literal
/reviewcommand was not invoked.