release: publish verified Wrangle 1.0.1 through CI - #57
Merged
Merged
Conversation
mikkokotila
enabled auto-merge
October 3, 2026 08:00
bit-mis
reviewed
Oct 3, 2026
bit-mis
left a comment
Collaborator
There was a problem hiding this comment.
Reviewed: no blocking findings.
bit-mis
reviewed
Oct 3, 2026
bit-mis
left a comment
Collaborator
There was a problem hiding this comment.
Reviewed: no blocking findings.
bit-mis
reviewed
Oct 3, 2026
bit-mis
left a comment
Collaborator
There was a problem hiding this comment.
Reviewed: no blocking findings.
bit-mis
previously approved these changes
Oct 3, 2026
bit-mis
requested changes
Oct 3, 2026
bit-mis
left a comment
Collaborator
There was a problem hiding this comment.
Change requested in inline comments.
bit-mis
previously approved these changes
Oct 3, 2026
bit-mis
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Installing Wrangle from PyPI currently delivers the historical 0.7.6 interface.
The project owner explicitly designates
bit-misas the sole reviewer and code owner. Its automated approval satisfies the project review requirement; no separate human approval is required. The unrequested human-reviewer team and required-team rule have been deleted. Governance, contribution guidance and the shipped manual now match this decision without claiming independent human review. Required CI checks, stale-review dismissal, approval after the last push and no administrator bypass remain in place.GitHub reads CODEOWNERS from the base branch. The old-owner gate is disabled for this transition so it does not require the previous human owners to approve this PR. Once the reviewed CODEOWNERS change reaches master, code-owner enforcement can require bit-mis alone.
Release 1.0.1 makes the native Polars engine, YAML protocols, CLI and agent manual available under the existing
wranglepackage name.The release workflow retains separate build and provenance-signing jobs, then downloads and verifies the signed wheel/source archive before uploading those exact distributions to PyPI. Only the upload job receives the existing organization
PYPI_API_TOKEN; it has read-only GitHub access and does not check out or execute Wrangle source. Token-based publication retains GitHub/Sigstore provenance and does not claim PyPI index attestations.The README now gives direct PyPI installation and warns existing 0.x users to follow the migration guide. Release notes are dated for 1.0.1; generated manuals match the source. The measured Scorecard snapshot is updated to 8.7 on commit 9571e6d.
Validation of the release implementation (before the later ownership/governance documentation changes):
Review-policy correction validation: verified the human team is deleted, required-team reviewers are empty and the old-owner gate is disabled; before/after comparison confirms CI checks, last-push approval, stale-review dismissal and no bypass remain unchanged. CODEOWNERS names only bit-mis; generated documentation and whitespace checks pass. CI reruns on
9186b7f.Publication remains pending: merge this PR after bit-mis approval and required checks, then publish tag v1.0.1 from the reviewed master commit. Verify the resulting PyPI 1.0.1 file hashes and fresh CLI preparation against the signed release assets.