Skip to content

[v1.0] Publish the post-0.4.3 fixes under a new package version #307

Description

@codeforester

Goal

Ship the validated changes on main as the immutable 0.5.0 release while keeping the published 0.4.3 artifact unchanged.

Background

PyPI and the latest GitHub release publish 0.4.3 from tag v0.4.3. Current main contains user-visible lifecycle, portability, Click 8.5, release-toolchain, typing, coverage, compatibility, and security hardening changes, but both VERSION and base_cli.__version__ still report 0.4.3.

The Package workflow builds review artifacts from main while that version remains unchanged. As a result, source documentation and validation results describe behavior that pip install base-cli==0.4.3 does not contain, and main artifacts reuse an already-published distribution identity.

Scope

  • Prepare and publish the next minor release as 0.5.0; keep 0.4.3 immutable.
  • Review the pre-1.0 SemVer/API impact and document any compatibility or migration notes.
  • Include all post-0.4.3 user-visible fixes under [Unreleased], then cut the dated 0.5.0 changelog section.
  • Resolve the open P1 release blocker from [v1.0] Gate releases on protected main lineage and independent approval #271 before tagging.
  • Rehearse TestPyPI, publish the exact reviewed artifact, and create the GitHub release.
  • Record checksums, SPDX SBOM, attestations, and installed-wheel validation.

Acceptance criteria

  • VERSION, package metadata, tag v0.5.0, GitHub release, changelog, and PyPI all agree on 0.5.0.
  • The release notes explain the 0.4.x to 0.5.0 compatibility boundary and link migration guidance where needed.
  • The published wheel includes the Click 8.5 compatibility range and every claimed post-0.4.3 fix.
  • No 0.4.3 artifact or tag is replaced.
  • TestPyPI and PyPI verification install from empty environments and pass the public lifecycle/JSON smoke tests.
  • The final release commit is protected and independently approved per [v1.0] Gate releases on protected main lineage and independent approval #271.
  • The release artifact, provenance, SBOM, and GitHub release all correspond to the same reviewed commit and tag.

Dependencies

Project fields

  • Status: Backlog
  • Priority: P1
  • Area: Packaging
  • Initiative: v1.0 Readiness
  • Size: M

Ownership

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or product improvement

Projects

  • Status
    Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions