diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5880461..251bb17 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,7 +7,7 @@ name: release # For a project that does not exist yet, register it as a PENDING publisher; the # first successful run creates the project. Then set the repository variable # PYPI_ENABLED to 'true' and push a tag: -# git tag v0.2.0 && git push origin v0.2.0 +# git tag v0.2.2 && git push origin v0.2.2 # # Actions are pinned by commit SHA, not by tag. A moving tag is a supply-chain # hole, and this is a project about verifiable provenance. diff --git a/CHANGELOG.md b/CHANGELOG.md index 4d0cfb3..52658da 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,8 +1,14 @@ # Changelog -## Unreleased +## 0.2.2 - 2026-09-22 -No changes yet after the 0.2.1 release-prep branch. +- Adds an OIDC trusted-publishing release workflow. No token is stored anywhere. + A tag builds the sdist and wheel, checks the tag against the declared version, + records artifact digests in the run log, installs the wheel into a clean venv + and resolves every console script, then rebuilds a wheel from the sdist before + anything is published. +- Publishes to PyPI as `plexus-mesh`. The console script stays `plexus`. No + runtime behavior changed in this release. ## 0.2.1 diff --git a/pyproject.toml b/pyproject.toml index f972c14..1c02e61 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "plexus-mesh" -version = "0.2.1" +version = "0.2.2" description = "Declarative capability discovery + auto-wiring for agent toolchains: point it at tool manifests and it wires producer to consumer into an executable pipeline, every discovery edge tagged declared and citing the module its producer names. Discovery does not import or run cited tools; optional explicit probe helpers can launch owned MCP servers. Zero runtime dependencies." readme = "README.md" requires-python = ">=3.11" @@ -31,3 +31,13 @@ Homepage = "https://github.com/HarperZ9/plexus" [tool.setuptools.packages.find] where = ["src"] + +[tool.pytest.ini_options] +# Without this, pytest imports whatever copy of the package happens to be +# installed in the environment instead of this repo's src/. That is not a +# style preference: chorus was resolving to a stale editable install pointing +# at an old worktree, and plexus to a copy in site-packages, so both suites +# were green while testing source that was not this checkout. +pythonpath = ["src"] +testpaths = ["tests"] +addopts = "-q" diff --git a/src/plexus/__init__.py b/src/plexus/__init__.py index 627000d..b86a846 100644 --- a/src/plexus/__init__.py +++ b/src/plexus/__init__.py @@ -14,7 +14,7 @@ from .registry import builtin_manifests, load_dir from .run import pipeline_script -__version__ = "0.2.1" +__version__ = "0.2.2" __all__ = [ "Manifest", "Port", "validate", diff --git a/tests/test_release_metadata.py b/tests/test_release_metadata.py index ee06d22..656e535 100644 --- a/tests/test_release_metadata.py +++ b/tests/test_release_metadata.py @@ -4,7 +4,7 @@ ROOT = Path(__file__).resolve().parents[1] -VERSION = "0.2.1" +VERSION = "0.2.2" def test_release_identity_is_aligned():