Make SDK preview publication opt-in - #100
Merged
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
lelia
marked this pull request as ready for review
August 5, 2026 17:23
Phil Gran (philgran)
approved these changes
Aug 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replace the always-on TestPyPI preview job with two separate concerns:
Package Checkruns deterministically on every PR and onmain. It runs the SDK unit tests, builds the wheel and sdist, validates them with Twine, installs the wheel in a clean environment, runs an import smoke test, and uploads the distributions as workflow artifacts.Publish PR Previewruns only when explicitly requested through thepublish-previewlabel or manual workflow dispatch.The companion CLI implementation is SocketDev/socket-python-cli#287.
Why
The previous preview check coupled code validation to TestPyPI publication and its cached Simple API. Recent uploads succeeded but the check waited for ten minutes and failed because the runner continued seeing a stale package index. Global “next
.devN” discovery also allowed concurrent PRs or stale index responses to select an already-used version, producing either collisions or false-green runs that skipped the current build.Implementation
.dev<run-id-and-attempt>suffix.uv lock; publishing no longer depends on rewriting the dependency lock.Opt-in usage
Apply the existing
publish-previewrepository label to a same-repository PR to publish one preview. Maintainers can alternatively run Publish PR Preview manually with the PR number.Review follow-up
Validation
actionlint .github/workflows/package-check.yml .github/workflows/pr-preview.ymlruff check .hooks/sync_version.pymaintwine checkuv.lockAfter this merges,
Package Checkcan be added to the branch-protection required checks.