Skip to content

fix(ci): drop the nonexistent twine --trusted-publishing flag - #539

Open
MichaelGHSeg wants to merge 1 commit into
masterfrom
fix/twine-publish-invocation
Open

MichaelGHSeg wants to merge 1 commit into
masterfrom
fix/twine-publish-invocation

Conversation

@MichaelGHSeg

Copy link
Copy Markdown
Contributor

The 2.4.0 publish failed here:

twine upload: error: unrecognized arguments: --trusted-publishing=always

twine has no such option in any version, so the upload aborted with exit 2 before contacting PyPI. Everything before it succeeded — Artifactory auth, tag/version validation, uv build.

Trusted publishing does not need a flag. twine resolves the password via keyring, then trusted publishing, then a prompt, and defaults the username to __token__ for PyPI; it fetches the audience from /_/oidc/audience, calls detect_credential, and mints a token at /_/oidc/mint-token by itself.

--non-interactive is added so a trusted-publishing failure errors out instead of trying to prompt for a password.

Nothing was published, so 2.4.0 is still unused on PyPI. After this merges the tag and release need recreating at the new master so the workflow that runs includes the fix.

twine has no such option, so the upload aborted with exit 2 before contacting
PyPI. Trusted publishing needs no flag: twine resolves the password through
keyring, then trusted publishing, and defaults the username to __token__ for
PyPI, fetching the audience and minting a token over OIDC on its own.

--non-interactive so a trusted-publishing failure errors instead of trying to
prompt for a password.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant