Ensure Sigstore CLI on downloads server is >= 3.6.2 and < 4#293
Merged
hugovk merged 3 commits intopython:mainfrom Nov 14, 2025
Merged
Ensure Sigstore CLI on downloads server is >= 3.6.2 and < 4#293hugovk merged 3 commits intopython:mainfrom
hugovk merged 3 commits intopython:mainfrom
Conversation
Member
Author
@sethmlarson Thoughts on this? |
Member
Author
|
I've removed the later check. I plan to merge this before Tuesday's 3.15.0a2. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
During the 3.15.0a1 release, after the release files had been signed by Sigstore I got this error during the verification:
This was fixed in Sigstore 3.6.2: sigstore/sigstore-python#1350
I upgraded my version of
sigstoreon the downloads server from 3.5.3 to 3.6.6 (the latest 3.6.x, and the latest 3.x that's <4) and it then worked.So let's adjust the "Checking Sigstore CLI" pre-check which runs at the start of the whole release, so instead of checking
>=3, it checks>= 3.6.2and<4.This original
>=3check was added in #194.We also have a second
sigstoreversion check later on.It's part of
add_to_pydotorg.py, which runs on the downloads server, and does the actual signing/verifying/uploading.This was added in #167.
I didn't change this to also check
>= 3.62, < 4. In fact, I think we could remove it because we have the pre-check above?