Disable attestations for prod PyPI publish (#5230)#5230
Closed
alibeklfc wants to merge 1 commit into
Closed
Conversation
Contributor
|
@alibeklfc has exported this pull request. If you are a Meta employee, you can view the originating Diff in D106110673. |
alibeklfc
added a commit
to alibeklfc/faiss
that referenced
this pull request
May 22, 2026
Summary: Pull Request resolved: facebookresearch#5230 Disables Sigstore attestations (`attestations: false`) in the prod PyPI publish step. The `pypa/gh-action-pypi-publish` action generates attestation certificates that carry the top-level workflow (`build.yml`) as the Build Config URI, but PyPI verifies attestations against the trusted publisher which is configured as `build-pip.yml` (the reusable workflow where the publish job is defined). This mismatch causes a `400 Invalid attestations` rejection when `build.yml` calls `build-pip.yml` via `workflow_call`. TestPyPI is unaffected because `workflow_dispatch` triggers `build-pip.yml` directly, so the certificate and publisher both say `build-pip.yml`. This is a known limitation of `pypa/gh-action-pypi-publish` with reusable workflows. Attestations can be re-enabled once PyPI supports matching against `workflow_ref` in addition to `job_workflow_ref` for attestation verification, or once the publish job is moved out of the reusable workflow. Reviewed By: mnorris11 Differential Revision: D106110673
1301162 to
bc1e13c
Compare
Summary: Pull Request resolved: facebookresearch#5230 Disables Sigstore attestations (`attestations: false`) in the prod PyPI publish step. The `pypa/gh-action-pypi-publish` action generates attestation certificates that carry the top-level workflow (`build.yml`) as the Build Config URI, but PyPI verifies attestations against the trusted publisher which is configured as `build-pip.yml` (the reusable workflow where the publish job is defined). This mismatch causes a `400 Invalid attestations` rejection when `build.yml` calls `build-pip.yml` via `workflow_call`. TestPyPI is unaffected because `workflow_dispatch` triggers `build-pip.yml` directly, so the certificate and publisher both say `build-pip.yml`. This is a known limitation of `pypa/gh-action-pypi-publish` with reusable workflows. Attestations can be re-enabled once PyPI supports matching against `workflow_ref` in addition to `job_workflow_ref` for attestation verification, or once the publish job is moved out of the reusable workflow. Reviewed By: mnorris11 Differential Revision: D106110673
bc1e13c to
0ae9262
Compare
Contributor
|
This pull request has been merged in 8f03848. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary:
Disables Sigstore attestations (
attestations: false) in the prod PyPI publish step. Thepypa/gh-action-pypi-publishaction generates attestation certificates that carry the top-level workflow (build.yml) as the Build Config URI, but PyPI verifies attestations against the trusted publisher which is configured asbuild-pip.yml(the reusable workflow where the publish job is defined). This mismatch causes a400 Invalid attestationsrejection whenbuild.ymlcallsbuild-pip.ymlviaworkflow_call.TestPyPI is unaffected because
workflow_dispatchtriggersbuild-pip.ymldirectly, so the certificate and publisher both saybuild-pip.yml.This is a known limitation of
pypa/gh-action-pypi-publishwith reusable workflows. Attestations can be re-enabled once PyPI supports matching againstworkflow_refin addition tojob_workflow_reffor attestation verification, or once the publish job is moved out of the reusable workflow.Reviewed By: mnorris11
Differential Revision: D106110673