Compare commits
1 Commits
9d2bab9a38
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 47b743a074 |
@@ -70,6 +70,12 @@ Gitea rejects secret names prefixed with `GITEA_` — use `PACKAGE_USER` / `PACK
|
||||
The publish workflow fails at the upload step when either secret is missing or
|
||||
invalid. Do not commit tokens to the repository.
|
||||
|
||||
**Smoke-test result (2026-06-16):** `workflow_dispatch` run #17 built and passed
|
||||
`twine check`; upload returned `401 Unauthorized`. That indicates
|
||||
`PACKAGE_USER` / `PACKAGE_TOKEN` repo secrets need verification (token must
|
||||
include `write:package`, username must match the token owner). Build step uses
|
||||
`.build-venv` and is PEP 668 safe on haskelseed.
|
||||
|
||||
Verify secrets without cutting a release:
|
||||
|
||||
1. Open **Actions → Publish Python package → Run workflow** (`workflow_dispatch`),
|
||||
|
||||
Reference in New Issue
Block a user