[Hotfix Main]: ci: add release-branch checks and manual approval for PyPI publish #1794
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hotfix of PR #1787 (#1787) to the
mainbranch.Hey @benflexcompute, please review this hotfix PR created from your original PR.
Note
Medium Risk
Changes the release/publish pipeline and adds new GitHub API-based gating and environment approval, which could block or delay releases if branch/tag/CI signals are misdetected.
Overview
PyPI publishing is now gated behind release source validation, manual environment approval, and a post-approval CI status re-check.
The workflow resolves the intended
release-candidate/*branch and pinned tag commit SHA for both tag pushes andworkflow_dispatch, rejects ambiguous/missing tag-to-branch mappings, and publishes from the exact tagged commit. It also changes manual dispatch input from a raw version to an explicit semvertag, and strips thevprefix when runningpoetry version.Written by Cursor Bugbot for commit 095c95a. This will update automatically on new commits. Configure here.