From 6f58678a7d5d9bc74ed6f205e39aabfa78c5dbd0 Mon Sep 17 00:00:00 2001 From: Louis Choquel Date: Thu, 27 Aug 2026 13:21:26 +0200 Subject: [PATCH] Bump the publish workflow's Sigstore action past the TUF root rotation The publish workflow pinned sigstore/gh-action-sigstore-python@v3.0.0, whose bundled sigstore-python predates the Sigstore TUF trust-root rotation. The "Sign the dists with Sigstore" step now fails deterministically with tuf.api.exceptions.UnsignedMetadataError: root was signed by 0/3 keys That step lives in the GitHub-release job, and PyPI publication is a separate job, so the failure mode is a version published to PyPI with no matching GitHub release or tag. That is exactly what happened to mthds-python v0.9.0 on the same pin. The pin now moves to v3.5.0, written as the SHA 790bc6befb9d733738f18d8f895854b453640ec9 to match how pipelex and mthds-python already carry it. The SHA matters beyond the usual supply-chain hygiene: the Actions allowlist is managed at the enterprise level and already permits this exact SHA, so any other version would need an admin to allowlist it first. Closes L-260826-abe686 Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01MLDh2h2fJhY9E3YFHQ1Ana --- .github/workflows/publish-pypi.yml | 2 +- CHANGELOG.md | 3 +++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish-pypi.yml b/.github/workflows/publish-pypi.yml index dc85b18..e9a928a 100644 --- a/.github/workflows/publish-pypi.yml +++ b/.github/workflows/publish-pypi.yml @@ -119,7 +119,7 @@ jobs: name: python-package-distributions path: dist/ - name: Sign the dists with Sigstore - uses: sigstore/gh-action-sigstore-python@v3.0.0 + uses: sigstore/gh-action-sigstore-python@790bc6befb9d733738f18d8f895854b453640ec9 # v3.5.0 with: inputs: >- ./dist/*.tar.gz diff --git a/CHANGELOG.md b/CHANGELOG.md index 85f4f09..675777b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,9 @@ ## [Unreleased] +### Fixed +- **CI:** Bumped the Sigstore signing action in the publish workflow from `v3.0.0` to `v3.5.0`, SHA-pinned as `790bc6befb9d733738f18d8f895854b453640ec9`. The sigstore-python bundled with `v3.0.0` predates the Sigstore TUF trust-root rotation, so the "Sign the dists with Sigstore" step had started failing deterministically with `tuf.api.exceptions.UnsignedMetadataError: root was signed by 0/3 keys`. That step sits in the GitHub-release job, so the failure mode was a version published to PyPI with no matching GitHub release or tag. + ### Changed - **Tooling:** Pinned `ruff` to an exact `0.16.4`, up from `0.14.13`. This matches what the Ruff VS Code extension now bundles, which matters because Ruff 0.16 lints `pyproject.toml` itself: the extension syncs the config file to the language server, and a pre-0.16 binary parses it as Python source and paints phantom `invalid-syntax` diagnostics on lines like `requires-python`. Keeping the pin exact stops the editor and the CLI from drifting apart again. Nothing shipped changes — this is a dev dependency, and the upgrade produced no new lint findings and no reformatting.