Skip to content

Bump yara-python-dex to 1.1.0 and fix publishing - #8

Merged
ajinabraham merged 3 commits into
update-cifrom
bump-1.1.0
Sep 21, 2026
Merged

ajinabraham merged 3 commits into
update-cifrom
bump-1.1.0

Conversation

@ajinabraham

Copy link
Copy Markdown
Member

Summary

  • Bump the package to 1.1.0 and switch releases to PyPI trusted publishing (OIDC via pypa/gh-action-pypi-publish, GitHub environment pypi).
  • Fix the 1.0.8 / 1.0.9 publish failures: unique per-job artifact names, merge them on download, and drop the QEMU ARM workflow in favor of ubuntu-24.04-arm.
  • Update GitHub Actions (checkout@v7.0.1, setup-python@v7.0.0, upload-artifact@v7.0.1, download-artifact@v8.0.1) and cover future CPython versions with cpython-prerelease plus weekly Dependabot for pypa/cibuildwheel.

Stacked on #7.

Why 1.0.8 and 1.0.9 never reached PyPI

PyPI latest is still 1.0.7. Release logs have expired, but the run metadata plus the workflow YAML at each tag are enough:

  • 1.0.8 (Build & Publish, ARM) failed in ~7s before any steps ran. Both workflows still used actions/upload-artifact@v3 / download-artifact@v3 (ARM also used actions/checkout@v3). GitHub disabled those Node 16 artifact actions on 30 Jan 2025; the release was 31 Aug 2025.
  • 1.0.9 (Build & Publish) upgraded to upload-artifact@v4.6.2 but kept the artifact name wheels for every matrix job. v4 artifacts are immutable, so Ubuntu uploaded first, Windows then failed with a name conflict, and macOS/ARM were cancelled. Publish never ran.

Trusted publishing (one remaining PyPI click)

Repo environment pypi is already created. After merge, a PyPI maintainer still needs to add this GitHub publisher at https://pypi.org/manage/project/yara-python-dex/settings/publishing :

  • Owner: MobSF
  • Repository: yara-python-dex
  • Workflow: build_publish.yml
  • Environment: pypi

Until that publisher exists, the next release upload will fail OIDC minting.

Test plan

  • Confirm Build Test and Test pass on this PR (linux, linux-arm, windows, macos).
  • After merge of Python 3.14 & 3.15 support, bump cibuildwheel to 4.2.1 #7 and this PR, add the PyPI trusted publisher with the fields above.
  • Cut a GitHub release for 1.1.0 and confirm wheels upload without PYPI_USERNAME / PYPI_PASSWORD.
  • Check that artifact names are unique (wheels-ubuntu-latest, wheels-ubuntu-24.04-arm, etc.) and that the publish job sees all of them.

Made with Cursor

ajinabraham and others added 3 commits September 20, 2026 18:25
Unique per-job artifact names are required after upload-artifact v4, which is why 1.0.9 never reached PyPI. Enable CPython prereleases and Dependabot so new Python versions land with cibuildwheel updates.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop long-lived PyPI credentials in favor of OIDC via gh-action-pypi-publish and a dedicated pypi environment.

Co-authored-by: Cursor <cursoragent@cursor.com>
Tags already matched the latest releases; pinning the commit hashes stops a retagged action from changing under us while Dependabot can still bump the SHA and version comment.

Co-authored-by: Cursor <cursoragent@cursor.com>
@ajinabraham
ajinabraham merged commit 1ab3c8a into update-ci Sep 21, 2026
10 checks passed
@ajinabraham
ajinabraham deleted the bump-1.1.0 branch September 21, 2026 01:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant