From dbf933d206d869fd9df98d70c4a56857ec272f95 Mon Sep 17 00:00:00 2001 From: Anto Subash Date: Wed, 22 Apr 2026 15:51:25 +0200 Subject: [PATCH 1/2] fix(release): grant actions:read so preflight can see pr.yml status The workflow-level permissions block only listed contents/id-token, which implicitly set actions to none. gh run list then returned nothing, the 2>/dev/null swallowed the error, and preflight spun out its 5-minute timeout even though pr.yml had already finished green. - add actions: read to the permissions block - drop 2>/dev/null so future gh failures are visible in the log --- .github/workflows/release.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d9fe08b7..4c155746 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,6 +16,7 @@ on: permissions: contents: write id-token: write # required for PyPI Trusted Publishing (OIDC); npm uses NPM_TOKEN + actions: read # preflight's `gh run list` needs this; omitting it silently returns empty env: NODE_VERSION: "24" @@ -54,7 +55,7 @@ jobs: --workflow pr.yml \ --branch main \ --json conclusion,status \ - --jq 'map(select(.status == "completed")) | .[0].conclusion' 2>/dev/null || true) + --jq 'map(select(.status == "completed")) | .[0].conclusion' || true) case "${conclusion:-}" in success) echo "pr.yml passed on ${{ github.sha }}" From c472f6ca557e1f1dd76dd2c798e7d05b1018ad7f Mon Sep 17 00:00:00 2001 From: Anto Subash Date: Wed, 22 Apr 2026 16:25:03 +0200 Subject: [PATCH 2/2] fix(hosting): drop redundant templates force-include causing wheel ZIP dupes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit packages = ["simple_module_hosting"] already includes the templates/ subdirectory and all its files (hatchling recurses into packaged dirs and picks up non-.py files too). The force-include entry re-added every file, producing 34 duplicate ZIP local headers. PyPI's upload validator rejects such archives with a 400. Other modules' force-include blocks stay — they ship package.json from the module root into the inner package dir, which hatchling wouldn't pick up from packages = [""] alone. Verified: wheel goes from 99 entries (34 dupes) to 65 entries (0 dupes), all 34 template files still shipped, twine check passes on all 14. --- framework/hosting/pyproject.toml | 3 --- 1 file changed, 3 deletions(-) diff --git a/framework/hosting/pyproject.toml b/framework/hosting/pyproject.toml index 38be3525..636659fe 100644 --- a/framework/hosting/pyproject.toml +++ b/framework/hosting/pyproject.toml @@ -50,9 +50,6 @@ build-backend = "hatchling.build" [tool.hatch.build.targets.wheel] packages = ["simple_module_hosting"] -[tool.hatch.build.targets.wheel.force-include] -"simple_module_hosting/templates" = "simple_module_hosting/templates" - [tool.uv.sources] simple_module_core = { workspace = true } simple_module_db = { workspace = true }