Make version.py the single source of the version, and correct RELEASING.md - #540
Merged
Merged
Conversation
pyproject.toml carried its own copy, and the publish workflow validated the tag only against that one. A stale version.py would therefore publish a correctly numbered package whose User-Agent and context.library.version reported the previous release, with nothing failing. hatchling now reads the version from version.py, and the tag check validates against the same file.
bsneed
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The version was duplicated, and only one copy was checked
pyproject.tomlheldversion = "2.4.0"andsegment/analytics/version.pyheld its ownVERSION. The publish workflow validated the release tag againstpyproject.tomlonly, butversion.pyis what the library actually reports at runtime:So a stale
version.pywould publish a correctly numbered package while every event it ever sent was attributed to the previous release — and nothing would fail.hatchling now reads the version from
version.pyvia[tool.hatch.version], and the tag check validates against that same file. Verified locally:uv buildresolves2.4.0fromversion.pyand names the sdist accordingly.RELEASING.md
Corrected against how 2.4.0 actually shipped:
--trusted-publishing=always; no such flag exists and it aborted the first attemptproductionenvironment requires review, so the publish job pauses — that step was missing