Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/python/release-tools

Scripts for making (C)Python releases
https://github.com/python/release-tools

gh-115582 and gh-115545: Windows release build mixes up free-threaded files (#98)

58a7c9111f25e655ac16e3553d3e7a479b510afb authored 11 months ago by Steve Dower <[email protected]>
Remove redundant blank lines

ff37a1d5ed256b32013f90fb62a8e533d10be3b6 authored 11 months ago by yancong <[email protected]>
Fix Windows release build (#97)

Signed builds were not including free-threaded binaries in the installer
Nuget packages need to...

a6512b358d483d7b7fbe840f10bd17bb0205794f authored 11 months ago by Steve Dower <[email protected]>
Add pip to SBOM at release stage

Co-authored-by: Ezio Melotti <[email protected]>

d29c9c3bb053831a54b3e593caa04e58d1f632a3 authored 11 months ago by Seth Michael Larson <[email protected]>
Strip whitespace from commit SHA

69f572e8f1519566b10aa0d2c6f8ff9f0d6a592a authored 11 months ago by Seth Michael Larson <[email protected]>
Sort arrays in SBOM JSON data for reproducibility

e2c2bb11d37241aa4432164b42d48bed7300d9ac authored 11 months ago by Seth Michael Larson <[email protected]>
Add Dependabot to keep GitHub Actions up-to-date

5b7ef459c76de94be909b02087080b4cc8befeed authored 11 months ago by Hugo van Kemenade <[email protected]>
Add test suite and GitHub Actions CI

Co-authored-by: Hugo van Kemenade <[email protected]>

8650935702f3536b986846a345a19743d9dcecb1 authored 11 months ago by Seth Michael Larson <[email protected]>
Merge pull request #89 from Yhg1s/typofix

Correct location of the regen-configure.sh script in 3.12+.

f39e1557464bc7d14019a88cb8257545ed4104f3 authored 11 months ago by T. Wouters <[email protected]>
Correct location of the regen-configure.sh script in 3.12+.

cad2dfe3f900b4b50786905a2f893036d05ef570 authored 11 months ago by Thomas Wouters <[email protected]>
Merge pull request #82 from sethmlarson/sbom-utility

Create utility for generating SBOM from artifacts

a048b9db2f48d7d69ed5c486af795a757614c768 authored 11 months ago by T. Wouters <[email protected]>
Merge pull request #87 from sethmlarson/make-regen-configure-fix

Run regen-configure script if available

38ce4f499be9e5a600af83e0fd1ef8e530098963 authored 11 months ago by T. Wouters <[email protected]>
Use regen-configure.sh when available, otherwise fallback to Docker

cacde86df037ec4532ad88567ca1d598cbb230a0 authored 11 months ago by Seth Michael Larson <[email protected]>
Bump aiohttp from 3.9.0 to 3.9.2

Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.9.0 to 3.9.2.
- [Release notes](http...

1118504e6b70a66d5df5b574bc3dbd24df7c6370 authored 11 months ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Add example of how to run script

a1d4092324a7c023cdc01bd555aef2d0f9f8060f authored 12 months ago by Seth Michael Larson <[email protected]>
Apply suggestions from code review

Co-authored-by: Hugo van Kemenade <[email protected]>
Co-authored-by: Ezio...

7cec3f5401fd753355396f2627e5f5a4e8e70931 authored 12 months ago by Seth Michael Larson <[email protected]>
Add SPDX SBOM files to python.org releases

c94bd5e4b55ea32500ecc4d2b8332c56c0c069bc authored 12 months ago by Seth Michael Larson <[email protected]>
Implement free-threaded build for the Windows release (#81)

76e1f69891816cca6feb11840ccf5b79b341be4f authored 12 months ago by Steve Dower <[email protected]>
Add SBOM build step to run_release.py

b1ce47207e412ff8403a0c53f7ceea42cf5c40d7 authored 12 months ago by Seth Michael Larson <[email protected]>
Addresses external reviewer feedback

* Adds dependency relationships between top-level
CPython package and vendored packages.
* Rem...

9b1fdfa9605a9e71ff32333cb2e71ad3304ceed6 authored 12 months ago by Seth Michael Larson <[email protected]>
Create utility for generating SBOM from artifacts

12982a19ce5f222ad54ff2666d059b12d019d079 authored 12 months ago by Seth Michael Larson <[email protected]>
Bump paramiko from 3.2.0 to 3.4.0

Bumps [paramiko](https://github.com/paramiko/paramiko) from 3.2.0 to 3.4.0.
- [Commits](https://...

e09c9a79d997a7fb91956a78c578b5f03409317e authored about 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Use 'regen-configure' Makefile target

12b269b596abe0080431d8b33629ffccfddf440f authored about 1 year ago by Seth Michael Larson <[email protected]>
Bump cryptography from 41.0.4 to 41.0.6

Bumps [cryptography](https://github.com/pyca/cryptography) from 41.0.4 to 41.0.6.
- [Changelog](...

5fe2dff425322d101c3924be98eed5cc2c50e749 authored about 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bump aiohttp from 3.8.6 to 3.9.0

Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.8.6 to 3.9.0.
- [Release notes](http...

fd49fffd39559cba0236062f805fea1dcbb4aac4 authored about 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bump aiohttp from 3.8.5 to 3.8.6

Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.8.5 to 3.8.6.
- [Release notes](http...

f9361ffd039b026107afb33aed4f6a3228d066a3 authored about 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Fix some typos

5ad30da55e94ad6bad655db5d7b3b4edbd17db01 authored about 1 year ago by Hugo van Kemenade <[email protected]>
Remove old 3.4 directory

441a7afd31f5babe622a3a227fe941a5d3eacd37 authored about 1 year ago by Hugo van Kemenade <[email protected]>
Use 'main' in function name and description

1ad8b98c927d2dc39eed1ff0c95041e96b8f7334 authored about 1 year ago by Hugo van Kemenade <[email protected]>
Merge pull request #65 from python/dependabot/pip/urllib3-2.0.7

Bump urllib3 from 2.0.6 to 2.0.7

691fbbb5ced090bae60fcb948f4a2e46e665a817 authored about 1 year ago by Ezio Melotti <[email protected]>
Bump urllib3 from 2.0.6 to 2.0.7

Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.0.6 to 2.0.7.
- [Release notes](https...

6812d6ab6ce2d6653310fb395e7b826de701948a authored about 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Merge pull request #64 from Yhg1s/cleanup-subprocess

Clean up the uses of subprocess with shell=True, and switch from os.ystem to subprocess so failu...

ed68094efa7a0aab98b11aca361e4fe569d9e227 authored about 1 year ago by T. Wouters <[email protected]>
Clean up the uses of subprocess with shell=True, and switch from os.system

to subprocess so failures don't pass silently.

aa37cfefebc20dbb558d13eac34da8e53dac6ade authored about 1 year ago by Thomas Wouters <[email protected]>
Download redistributable VC files from cpython-bin-deps (#63)

Previously we would use whichever was installed on the build machine, which could result in down...

fe5ebc3c4604c6e6c93cc7ebb20ddccd0caecd2f authored over 1 year ago by Steve Dower <[email protected]>
Use recommended reproducibility options for tar (#62)

6a977f326f5b920d970a94bac1de0613d2ede739 authored over 1 year ago by Seth Michael Larson <[email protected]>
Allow verification of commit SHA when building a Windows release (#61)

60337932aa7e0a69ece47f4d66e0130f0b393532 authored over 1 year ago by Seth Michael Larson <[email protected]>
Run tests of built artifacts with -uall (#59)

a956086457d1ea56df848d11495ccf665ee12332 authored over 1 year ago by Łukasz Langa <[email protected]>
Fix warning about "blurb release" not executed (#57)

There was a double negative and it wasn't clear why release.py thought "blurb
release" wasn't e...

d5766e964e6428161cae86470c7542a99fcfdaa5 authored over 1 year ago by Łukasz Langa <[email protected]>
Merge pull request #60 from python/dependabot/pip/urllib3-2.0.6

Bump urllib3 from 2.0.4 to 2.0.6

15646d5e8012db41c4a8a0bd4d3beffcb15579c0 authored over 1 year ago by Ezio Melotti <[email protected]>
Bump urllib3 from 2.0.4 to 2.0.6

Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.0.4 to 2.0.6.
- [Release notes](https...

7f7153377aca90bec25eaf6c628f5bd5eee5e599 authored over 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bump cryptography from 41.0.2 to 41.0.4 (#58)

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+d...

61c9085a713104982b98318041ad7bd147290735 authored over 1 year ago by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: remove "Release" and "Date" from whatsnew (#52)

The "Release" and "Date" fields are no longer needed in the What's New
pages, so I removed them...

6c6a5d9ec83fdb6ab0dde16837605ff32f00c1b6 authored over 1 year ago by Oliver Rew <[email protected]>
Use a lockfile with hashes for dependencies (#53)

b0a8efffc4a3507a9a1a08e6daaa9a7b5aacb0c6 authored over 1 year ago by Seth Michael Larson <[email protected]>
Fix minor version RM lookup (#54)

Co-authored-by: Seth Michael Larson <[email protected]>

8a66d95a3d93af799e5740053478c45eb79d0e70 authored over 1 year ago by Łukasz Langa <[email protected]>
Verify after signing that identity and provider are as documented (#51)

Co-authored-by: Łukasz Langa <[email protected]>

23b7714fee14b5325abd5a530a3e5c6fd658ef31 authored over 1 year ago by Seth Michael Larson <[email protected]>
Improve Windows build of OpenSSL 3.0 (#50)

b1875eb126aaeeaef89055302c5dfb6651366d17 authored over 1 year ago by Steve Dower <[email protected]>
Ensure publish steps always come after anything that might intermittently fail (#49)

f49e93d93980e96762d6009e33c7def39e760429 authored over 1 year ago by Steve Dower <[email protected]>
Improved Windows publish readme and fixed directory perms (#48)

f500b2173d32ab2c066377685a6e451c5f656a10 authored over 1 year ago by Steve Dower <[email protected]>
Make Tix optional when building Tcl/Tk binaries (#47)

8485d3b4d77a2559cbb3cf2e63dee43070327d50 authored over 1 year ago by Steve Dower <[email protected]>
Merge pull request #44 from Yhg1s/fix-issue-30

0584b56bb6b73a7eeac3c5837d2950b74a365982 authored almost 2 years ago by Pablo Galindo Salgado <[email protected]>
Fix #30 by refactoring the needs-download-button logic into the

file_description matching.

819af73e38603262ae80b718535a6fabfa35386f authored almost 2 years ago by Thomas Wouters <[email protected]>
Mark readline import as special

b3e3d3afdd8834952f77ddb9fc788f7097dae6ea authored almost 2 years ago by Łukasz Langa <[email protected]>
Merge pull request #43 from di/sigstore-1.1.1

Use the Sigstore 1.x API instead of CLI

5c1558c3b4c12e70a61b7b8a6f2aab414ec0f133 authored almost 2 years ago by T. Wouters <[email protected]>
Use the Sigstore 1.x API instead of CLI

e15053a7f3002a3c399df697158f846a8ac0122c authored almost 2 years ago by Dustin Ingram <[email protected]>
Sigstore 1.1.1 (#42)

d9996a13cc15734b78ca862f0b7ac5c30d81c25c authored almost 2 years ago by T. Wouters <[email protected]>
Merge pull request #40 from di/sigstore-bundles

Add support for Sigstore bundle files

5ea7286ff3e4538e2c816bb9f37cfc7720783fdc authored almost 2 years ago by T. Wouters <[email protected]>
Publish PGO binaries with correct name for signing (#41)

Without this, a signed build would upload the unsigned binaries with the incorrect artifact name...

0c4db470cbe028da8ee6986d29509cedf3e5da7f authored almost 2 years ago by Steve Dower <[email protected]>
Add support for Sigstore bundle files

0fa65773214b78fee68801c880dc2a7951c07dcf authored almost 2 years ago by Dustin Ingram <[email protected]>
Avoid failing on 3.10 and earlier due to missing deepfreeze/frozen_modules (#39)

d3c2fd1e985d364761081f7d642790dfabf501c8 authored almost 2 years ago by Steve Dower <[email protected]>
Enables PGO in Windows ARM64 release builds (#38)

00a8ad05fc16178fe91ec8923048579a7991ea4e authored almost 2 years ago by Steve Dower <[email protected]>
Enables building and signing OpenSSL, LibFFI and Tcl/Tk with Azure Key Vault (#37)

991e18f86e5687b03b2397879e55bf9966635db2 authored almost 2 years ago by Steve Dower <[email protected]>
Update Windows release build to include upload script here instead of in the source repo (#36)

09bee2ac58ff6fb5922281a402fd75392d2094dd authored almost 2 years ago by Steve Dower <[email protected]>
Enable use of Azure Key Vault to store code signing certificate for Windows releases (#35)

This updates the build process for Windows release builds to sign using Azure Key Vault (through...

fed1b717f37bfd98f64cc4d10196eb2c9e64dfd8 authored almost 2 years ago by Steve Dower <[email protected]>
Update Windows Release scripts to run correct tkinter tests (#32)

Automatically select correct ttk tests.
Output SHA256 hashes as well as MD5

a8894a378b250a7dc16b8fb88b5a88865e56bc33 authored about 2 years ago by Steve Dower <[email protected]>
Add 3.12 release manager to Windows Release build list of remotes (#31)

e7e59f3a4c9c93d6f6f072995139b2b08d08be84 authored about 2 years ago by Steve Dower <[email protected]>
Merge pull request #29 from python/pablogsal-patch-1

Add more pages to the CDN purge step

6ff8f09cf1e566c064406d30b2fdedd593bb661a authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Update run_release.py

01f4384db19f90556ad45ab127d480c1778ea0ad authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Add more pages to the CDN purge step

5270f87592f862f898b7a92293634137ff0b1bd1 authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Allow skipping tests in Windows release builds (#28)

c02b199d0421bc6ec9dbc317cc0db9e545f5296e authored about 2 years ago by Steve Dower <[email protected]>
Only chmod 644 files that `sigstore sign` produced just now

6846215910b2bd6db82f21fd68289afe8c5b8f76 authored about 2 years ago by Łukasz Langa <[email protected]>
Fix discovery whether artifacts already signed by Sigstore; and *use* the result

21e1adaf9b04ffbcf8d3699bf11f1ecac3db239c authored about 2 years ago by Łukasz Langa <[email protected]>
Merge pull request #27 from di/fix/25

f748fb88dad752a8af6d0e7fe74a786e4c0cc181 authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Fix usage of Sigstore env var

b14680a4fb53d3fc1d471e82a7e7130a5d2f1af3 authored about 2 years ago by Dustin Ingram <[email protected]>
Merge pull request #26 from python/sigstore2

a816ce494c3d65ad9838e272272dac70052ca8af authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Fix some problems with the sigstore changes

5114c56f0c63c4d2ee56c4cf95d478322923b43a authored about 2 years ago by Pablo Galindo <[email protected]>
Merge pull request #22 from di/fix-sigstore-signing

0ff14d97f8df1e49489f0dfc1787ef6d4a75839e authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Merge pull request #23 from python/whatsnew-issues-tweaks

8cf244b492d56a215559f18990dd19378de91e7d authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Merge pull request #24 from carljm/patch-1

be7be5e83c57c1f757fcdd4d6c05d94b0eb640c2 authored about 2 years ago by Pablo Galindo Salgado <[email protected]>
Update whatsnew template

Use `:gh:` instead of `:issue:`, clarify that it should be the GH issue number, and remove Mercu...

1d267727f454e64b0ef11712072b13fe3647a195 authored about 2 years ago by Carl Meyer <[email protected]>
Issues-related whatsnew template tweaks.

Co-authored-by: Carl Meyer <[email protected]>

c4a975db994d0a1ef71ac66eb3b1745615edefb9 authored about 2 years ago by Ezio Melotti <[email protected]>
Switch to directly importing sigstore

0b0e1cd931283379428954214d70cdfd7514a2e0 authored over 2 years ago by Dustin Ingram <[email protected]>
Formatting

b846e1339ebacde647822f4509735d23d7c1fc4b authored over 2 years ago by Dustin Ingram <[email protected]>
Update release.py

Co-authored-by: Ezio Melotti <[email protected]>

552bd554bba62a3639fdafe6795cf20187cdff81 authored over 2 years ago by Dustin Ingram <[email protected]>
Write signatures to base_version(release) dir

708e48e17f3ddc5ce21dceec8b5a26f5d3e00bd5 authored over 2 years ago by Dustin Ingram <[email protected]>
Revert "Comment the sigstore process until is ready"

This reverts commit 75e91ab6d083cd838911652a081117f036d44dab.

c2a1c1090ac833b0a8b21a3dc2ef6ad1a7091aff authored over 2 years ago by Dustin Ingram <[email protected]>
Get an identity token for Sigstore before running add-to-pydotorg

a9ee86b67706ed9ca7e7cec957d16264552e973b authored over 2 years ago by Dustin Ingram <[email protected]>
Update sigstore requirement

b24515314de074a2995a4b7f29e46693c69389d9 authored over 2 years ago by Dustin Ingram <[email protected]>
Set the right file permissions

bca6028aa8841a9777c627f319bf5e7111339eb0 authored over 2 years ago by Dustin Ingram <[email protected]>
Merge pull request #20 from python/sigstore

0859e21efb2c3d3a8ee63115c48d3a554e59d3ad authored over 2 years ago by Pablo Galindo Salgado <[email protected]>
Comment the sigstore process until is ready

75e91ab6d083cd838911652a081117f036d44dab authored over 2 years ago by Pablo Galindo <[email protected]>
Merge pull request #19 from python/pablogsal-patch-1

401afdec47eadf4b5f17a68f5bb87f4ca04a86d1 authored over 2 years ago by Pablo Galindo Salgado <[email protected]>
Fix name error in has_sigstore_signature

d96fb63e97698f603f6bfc7a9531b2073ee49b86 authored over 2 years ago by Pablo Galindo Salgado <[email protected]>
Merge pull request #17 from di/sigstore-updates

Sign w/ Sigstore and upload Sigstore verification materials

d5efa5a96546d0191e9e522b35266d4541c45b81 authored over 2 years ago by Pablo Galindo Salgado <[email protected]>
Copypasta run_cmd

e011b02fc0196c104499044c12b47a41e9c9caf3 authored over 2 years ago by Dustin Ingram <[email protected]>
Add build scripts for external Windows dependencies (#18)

24c7dd575e8a28bf6d32f6a7f1f6aa8c7f8d3dc9 authored over 2 years ago by Steve Dower <[email protected]>
Add sigstore as dependency

c1b2e850cef70fe2050d600032185fd8397e879e authored over 2 years ago by Dustin Ingram <[email protected]>
Sign all release files with Sigstore prior to upload

0f273aaf9e3d480abc5a5562fcdaf89e77e0b305 authored over 2 years ago by Dustin Ingram <[email protected]>
Don't include .sig and .crt files in release files

345f45ae6c38926eb2ede74213923571a4abad3e authored over 2 years ago by Dustin Ingram <[email protected]>
Add step to sign tarballs w/ Sigstore

2e3b03c435623b29cf9eed8e06e3e7afd541fdac authored over 2 years ago by Dustin Ingram <[email protected]>
Add Sigstore verification materials to upload

3851c2bd4413a738089fadcea806da0208224b13 authored over 2 years ago by Dustin Ingram <[email protected]>