Skip to content

Gate v1 publication on final-RC integration and built-artifact verification #5

Description

@BenWestgate

V1 publication must qualify the exact wheel/sdist bytes that are later published.

Required release gate:

  1. freeze the source commit and require the normal supported Python/OS checks;
  2. run the real Bitcoin Core v32 integration/fixture checks on the release candidate;
  3. run optimized/static/differential qualification;
  4. build wheel and sdist once;
  5. install those exact artifacts into clean qualification environments;
  6. record commit, package/tag, dependency/Core versions and SHA256/provenance;
  7. publish only the same qualified bytes.

Implemented in focused PR #52. Current head a653876 is mergeable and exact-head Python-package run 278 passed. The workflow stages qualified artifacts on a draft GitHub release, rechecks hashes/provenance immediately before publication, publishes to PyPI, then makes the GitHub release public. The tag-push publication path cannot execute from the PR itself and still requires the normal release-environment approval on the first real tag.

Bitcoin Core v32.0rc2 remains the currently recorded signed v32 candidate in #52; the separate release monitor will repin only when a newer signed RC or stable v32.0 appears. Keep this issue open until #52 is integrated and the final frozen candidate reaches the actual release-qualification step.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: packaging/releasePackaging, artifacts, compatibility, and release qualification.enhancementNew feature or requestgate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions