From 7263ed7ab4a5d75ec2b1b24c9798e7f623706038 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Sat, 1 Aug 2026 01:09:26 +0000 Subject: [PATCH 1/4] chore(deps): update pypa/gh-action-pypi-publish digest to dc37677 --- .github/workflows/release-please.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index fa55514..4a654f3 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -103,6 +103,6 @@ jobs: path: dist/ - name: Publish to PyPI - uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 with: print-hash: true From 478447462e5d070976df1454a0bb2e501043f76f Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 11:16:28 -0700 Subject: [PATCH 2/4] fix(deps): validate distributions before PyPI publishing --- .github/requirements-twine.txt | 1 + .github/workflows/release-please.yml | 5 ++++- .github/workflows/test.yml | 3 +++ 3 files changed, 8 insertions(+), 1 deletion(-) create mode 100644 .github/requirements-twine.txt diff --git a/.github/requirements-twine.txt b/.github/requirements-twine.txt new file mode 100644 index 0000000..54f4fd7 --- /dev/null +++ b/.github/requirements-twine.txt @@ -0,0 +1 @@ +twine==7.0.0 diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 4a654f3..10dc87c 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -62,12 +62,15 @@ jobs: - name: Build package run: uv build + - name: Check distribution metadata with Twine + run: uvx --from twine --constraints .github/requirements-twine.txt twine check --strict dist/* + - name: Verify package version matches release tag env: TAG: ${{ needs.release-please.outputs.tag_name }} run: | EXPECTED_VERSION="${TAG#promptfoo-v}" - if ls dist/*-${EXPECTED_VERSION}-*.whl 1> /dev/null 2>&1; then + if compgen -G "dist/*-${EXPECTED_VERSION}-*.whl" > /dev/null; then echo "✓ Package version ${EXPECTED_VERSION} matches release tag ${TAG}" else echo "ERROR: Package version mismatch!" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7067c19..c9e78c3 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -238,6 +238,9 @@ jobs: - name: Build package run: uv build + - name: Check distribution metadata with Twine + run: uvx --from twine --constraints .github/requirements-twine.txt twine check --strict dist/* + - name: Upload artifacts uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 with: From 98f018d0eaf783b968d29651b4809b942f5c83e5 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 10:37:57 -0700 Subject: [PATCH 3/4] ci(deps): isolate Windows npm installations --- .github/workflows/test.yml | 53 ++++---------------------------------- 1 file changed, 5 insertions(+), 48 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index c9e78c3..b13b54e 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -91,36 +91,12 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - # Add global bin directories to PATH - $binPaths = @($globalPrefix, (Join-Path $globalPrefix "bin")) | Where-Object { Test-Path $_ } - foreach ($binPath in $binPaths) { - $binPath | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - } - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" + $globalPrefix | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - name: Install promptfoo globally run: npm install -g promptfoo@latest @@ -171,30 +147,11 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" # Intentionally skip installing promptfoo globally # This tests the npx fallback path From 7198fd5ae585b58cae1cd56df21478fcea3eda00 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 11:33:32 -0700 Subject: [PATCH 4/4] fix(deps): keep Twine available for historical tags --- .github/workflows/release-please.yml | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 10dc87c..4d9dda7 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -42,9 +42,22 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - name: Check out publishing tool requirements from the workflow revision + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + ref: ${{ github.workflow_sha }} + persist-credentials: false + sparse-checkout: .github/requirements-twine.txt + sparse-checkout-cone-mode: false + + - name: Save publishing tool requirements for historical tags + run: cp .github/requirements-twine.txt "$RUNNER_TEMP/requirements-twine.txt" + + - name: Check out the release tag + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: ref: ${{ needs.release-please.outputs.tag_name }} + persist-credentials: false - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: @@ -63,7 +76,7 @@ jobs: run: uv build - name: Check distribution metadata with Twine - run: uvx --from twine --constraints .github/requirements-twine.txt twine check --strict dist/* + run: uvx --from twine --constraints "$RUNNER_TEMP/requirements-twine.txt" twine check --strict dist/* - name: Verify package version matches release tag env: