- Version updated in
pyproject.tomlandsrc/loopgrid_verify/version.py. -
CHANGELOG.mdupdated. -
python -m pytest -qpasses. -
python scripts/release_check.pypasses. -
python -m buildsucceeds. -
python -m twine check dist/*succeeds. - Fresh virtual-environment install from the built wheel succeeds.
- Valid attested fixture exits
0and prints[OK] VERIFIED. - Tampered fixture exits
2and prints[FAIL] INVALID. - Legacy fixture exits
0and prints theLegacy/unattestedwarning. - GitHub Actions and CodeQL are green.
Configure a Trusted Publisher for:
- PyPI project:
loopgrid-verify - GitHub owner:
loopgridio - Repository:
loopgrid-verify - Workflow:
release.yml - Environment:
pypi
Do not store a PyPI API token in repository secrets when Trusted Publishing is configured.
- Create a fresh virtual environment.
-
pip install loopgrid-verify==<version>from PyPI. -
loopgrid-verify --versionreports the expected version. - Verify a valid fixture using an out-of-band trusted public key.
- Confirm the tampered fixture fails with exit code
2. - Update LoopGrid core/website documentation only after the package is publicly installable.