Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe release workflow now runs only for published releases. It enables the ChangesRelease Publishing
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Merge Risk: ⚪ Minimal · up to The identified version mismatch predates this change; no remaining issue blocks merging the trusted-publishing workflow after normal checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Closing per maintainer direction: the existing release path works and the baseline stays as-is. |
Removes workflow_dispatch from release.yml (a master dispatch must never be able to reach a publish job, tornadoapi-guard PR #23 precedent) and replaces the twine + TWINE_USERNAME/TWINE_PASSWORD path with PyPI trusted publishing (pypa/gh-action-pypi-publish, id-token: write, pypi environment, release published trigger aligned with guard-core).
Note for the maintainer: the PyPI project settings must list this repo, workflow release.yml, and environment pypi as the trusted publisher. Once merged and verified on the next release, the now-unreferenced TWINE_USERNAME/TWINE_PASSWORD secrets can be deleted.
Summary by CodeRabbit
VERSIONfile.