Skip to content

Releases: hynek/build-and-inspect-python-package

v3.0.1

Choose a tag to compare

@hynek hynek released this 30 Jul 06:20
v3.0.1
2abe76d

Fixed

  • To avoid uv configuration interference with the project that is being built, the installation of our own tools is now ran in a different directory. Additionally, UV_EXCLUDE_NEWER is unset. #240

v3.0.0

Choose a tag to compare

@hynek hynek released this 30 Jul 05:17
v3.0.0
12fab95

Security

  • Given the increase and supply-chain attacks and advancements in tooling (for example, pinact or GitHub's Dependabot), this action will stop force-tagging minor and micro releases. This means, there will be no @v3 or @v3.0 tag that gets updated and force-pushed with each update. Always tag with the full version and commit hash; use Zizmor to secure your actions if you can.

Changed

v2.18.0

Choose a tag to compare

@hynek hynek released this 11 May 07:03
v2.18.0
d44ca7d

Added

  • New input: skip-sdist to skip building the source distribution. #228

v2.17.0

Choose a tag to compare

@hynek hynek released this 27 Mar 07:46
v2.17.0
fe0a0fb

Fixed

  • The action now passes Zizmor in pedantic mode. #212

v2.16.0

Choose a tag to compare

@hynek hynek released this 26 Mar 16:14
v2.16.0
35116b2

Added

  • New include-free-threaded input. When set to 'true', free-threaded Python siblings (for example, 3.14t) are included in the version outputs for Python 3.14 and later, inserted inline after each matching version. #208

v2.15.0

Choose a tag to compare

@hynek hynek released this 19 Mar 14:47
v2.15.0
f3d069d

Added

  • The Python version used to build the package can now be configured using the python-version input. #191

v2.14.0

Choose a tag to compare

@hynek hynek released this 11 Oct 10:24
v2.14.0
efb823f

Changed

  • Update tools such that they work on Python 3.14 (which is now 3.x on GitHub Actions). #182

  • The action now ignores UV_PYTHON coming from the outside. #184

v2.13.0

Choose a tag to compare

@hynek hynek released this 16 Jun 05:52
v2.13.0
c52c3a4

Added

  • New output: package_name is the name of the built package as stored in metadata.
    #162

  • The package name is now part of the action summary which is helpful when you build more than one package from a repository.
    #169

Changed

  • All GitHub actions are now pinned to exact hashes for better reproducibility and mild security improvements.

    Since chosen prefix SHA-1 hash collision attacks exist, this is but security theater against serious attackers.

v2.12.0

Choose a tag to compare

@hynek hynek released this 22 Jan 05:49
v2.12.0
b5076c3

This release only updates our dependencies to support packaging metadata v2.4 (as created, for example, by recent Hatchling releases).

Note

To upload packages with metadata v2.4 (which is required for PEP 639 license metadata) using the official pypi-publish GitHub Action, you must make sure to use its v1.12.4 or later.

v2.11.0

Choose a tag to compare

@hynek hynek released this 15 Dec 13:27
v2.11.0
14c7e53

Added

  • New output: package_version is the version of the package that was built. #152