Skip to content

Make publication depend on every release gate #60

Description

@stefan-jansen

Findings: BR-022.

Ensure the tag workflow publishes only the exact candidate artifact after all correctness, parity,
platform, type, lint, coverage, documentation, packaging, security, and provenance checks pass for
that commit.

Primary surfaces: CI and release workflows, artifact digest and provenance verification, required
GitHub checks.

Acceptance:

  • A tag on a commit with any failing mandatory job cannot reach PyPI.
  • The published wheel digest equals the tested and approved artifact digest.
  • Release workflow tests exercise missing, failed, stale-commit, and digest-mismatch cases.
  • Trusted publishing remains credential-free and least-privileged.

Dependencies: Issues 13-19 and Milestones 1-2.


Plan reference: /home/stefan/ml4t/libraries/ml4t-backtest-dev/.workspace/work/backtest-stable-release/milestone-3/plan.md - Issue 20 in milestone 0.1.0-m3 - Compatibility and release enforcement.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions