Releases: hynek/build-and-inspect-python-package
Release list
v3.0.1
Fixed
- To avoid uv configuration interference with the project that is being built, the installation of our own tools is now ran in a different directory. Additionally,
UV_EXCLUDE_NEWERis unset. #240
v3.0.0
Security
- Given the increase and supply-chain attacks and advancements in tooling (for example, pinact or GitHub's Dependabot), this action will stop force-tagging minor and micro releases. This means, there will be no
@v3or@v3.0tag that gets updated and force-pushed with each update. Always tag with the full version and commit hash; use Zizmor to secure your actions if you can.
Changed
- Only updates of actions and build dependencies, notably including Twine 7 that adds support for packaging metadata 2.5 and PEP 794 – Import Name Metadata.
v2.18.0
Added
- New input:
skip-sdistto skip building the source distribution. #228
v2.17.0
v2.16.0
Added
- New
include-free-threadedinput. When set to'true', free-threaded Python siblings (for example,3.14t) are included in the version outputs for Python 3.14 and later, inserted inline after each matching version. #208
v2.15.0
Added
- The Python version used to build the package can now be configured using the
python-versioninput. #191
v2.14.0
v2.13.0
Added
-
New output:
package_nameis the name of the built package as stored in metadata.
#162 -
The package name is now part of the action summary which is helpful when you build more than one package from a repository.
#169
Changed
-
All GitHub actions are now pinned to exact hashes for better reproducibility and mild security improvements.
Since chosen prefix SHA-1 hash collision attacks exist, this is but security theater against serious attackers.
v2.12.0
This release only updates our dependencies to support packaging metadata v2.4 (as created, for example, by recent Hatchling releases).
Note
To upload packages with metadata v2.4 (which is required for PEP 639 license metadata) using the official pypi-publish GitHub Action, you must make sure to use its v1.12.4 or later.
v2.11.0
Added
- New output:
package_versionis the version of the package that was built. #152