Skip to content

Proposal: simplify the release/provenance machinery #113

Description

@richardmhope

Problem

The release and provenance tooling is large compared with what it ships:

  • about 1,000 lines across seven scripts,
  • 218 lines of provenance.py,
  • a 228-line release workflow, and
  • a near-duplicate of that pipeline in the CI build job.

All of this surrounds a ~1,000-line CLI with two runtime dependencies. Each extra step is something to keep working, and several don't add security, as described in the release-verification issue.

Proposed approach

This is for discussion, not a mandate.

Keep (these carry their weight):

  • Trusted Publishing behind a protected environment.
  • Build once, then publish the same bytes.
  • SHA-pinned actions, Dependabot, and per-job permissions.
  • build_plugin.py --check, check_release_consistency.py and prepare_release.py.
  • One actions/attest-build-provenance call covering the wheel and sdist.

Candidates to remove or shrink:

  • Replace verify_distribution_identity.py (403 lines) with build_plugin.py --check plus a short check that the wheel contains exactly the bundled skills.
  • Remove the dual content manifest, with four hashes per skill and a domain-separated digest. The build attestation already binds the artifact digest to the commit.
  • Remove _build_metadata.json stamping and stamp_build_metadata.py, for the same reason.
  • Remove the SBOM step and verify_sbom.py, or keep one plain SBOM without attesting it. For two open-ranged dependencies it's a snapshot rather than a bill of materials (see the reproducibility issue).
  • Merge the three attest calls into one.
  • Remove the tamper step, and reduce verify-channels to one gh attestation verify plus a PyPI digest comparison.
  • Replace the CI build job's copy of the release pipeline with a reusable workflow_call shared with release.yml. The two have already drifted: different uv cache settings and a different --tag check.

If the full machinery is intentional, for example as a reference implementation for #76, noting that in docs/releasing.md would settle the question.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions