Skip to content

ci: pin pypi-publish action to its commit sha, not the tag-object sha#6

Merged
anassg-lago merged 1 commit into
mainfrom
fix/pypa-publish-commit-sha
Jun 3, 2026
Merged

ci: pin pypi-publish action to its commit sha, not the tag-object sha#6
anassg-lago merged 1 commit into
mainfrom
fix/pypa-publish-commit-sha

Conversation

@anassg-lago

Copy link
Copy Markdown
Collaborator

The publish step failed with manifest unknown pulling ghcr.io/pypa/gh-action-pypi-publish:ecb4c3df… . That sha is the annotated tag object for v1.12.2 (what git ls-remote refs/tags/v1.12.2 returns), not the commit it points to. gh-action-pypi-publish is a Docker action and GitHub pulls the image tagged with the ref you pass; pypa publishes that image keyed by the commit sha (15c56dba…), so the tag-object sha has no image. Verified against ghcr.io: tag-object sha → 404, commit sha → 200.

Repin to the commit sha 15c56dba…; keeps SHA-pinning intact and resolves to the published image. (The other actions use lightweight tags, so their pins were already commit shas.)

The publish step failed with `manifest unknown` pulling
ghcr.io/pypa/gh-action-pypi-publish:ecb4c3df… . That sha is the annotated
tag *object* for v1.12.2 (what `git ls-remote refs/tags/v1.12.2` returns),
not the commit it points to. gh-action-pypi-publish is a Docker action and
GitHub pulls the image tagged with the ref you pass; pypa publishes that
image keyed by the commit sha (15c56dba…), so the tag-object sha has no
image. Verified against ghcr.io: tag-object sha → 404, commit sha → 200.

Repin to the commit sha 15c56dba…; keeps SHA-pinning intact and resolves to
the published image. (The other actions use lightweight tags, so their pins
were already commit shas.)
@anassg-lago
anassg-lago requested a review from chuckulele June 3, 2026 19:21
@anassg-lago
anassg-lago merged commit 4d43e02 into main Jun 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants