Skip to content

Update twine to v7 - #416

Merged
webknjaz merged 1 commit into
pypa:unstable/v1from
takluyver:twine-v7
Jul 28, 2026
Merged

webknjaz merged 1 commit into
pypa:unstable/v1from
takluyver:twine-v7

Conversation

@takluyver

Copy link
Copy Markdown
Member

Twine 7.0, which was just released, is required for uploading packages with Import-Name metadata, i.e. metadata version 2.5.

Comment thread requirements/runtime.txt Outdated
@@ -1,5 +1,5 @@
#
# This file is autogenerated by pip-compile with Python 3.13
# This file is autogenerated by pip-compile with Python 3.14

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plz generate the lock file using the same Python runtime as the docker container has.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, done!

@webknjaz webknjaz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I think this will get released together with the changes needed for #415 (at least it doesn't look like those blockers are too far away).

cc @facutuesca

@webknjaz
webknjaz merged commit 78b72db into pypa:unstable/v1 Jul 28, 2026
10 checks passed
@takluyver

Copy link
Copy Markdown
Member Author

Thank-you!

@takluyver
takluyver deleted the twine-v7 branch July 28, 2026 09:37
MImmesberger added a commit to ttsim-dev/ttsim that referenced this pull request Aug 20, 2026
The `v1.3.0` tag push built fine but failed at the upload gate:

```
Checking dist/ttsim_backend-1.3.0-py3-none-any.whl: ERROR
InvalidDistribution: Invalid distribution metadata: '2.5' is not a valid metadata version
```

(https://github.com/ttsim-dev/ttsim/actions/runs/32375860674)

The workflow installs `build` unpinned, so it picks up a current
hatchling, which emits `Metadata-Version: 2.5`. The Twine bundled in
`gh-action-pypi-publish@v1.14.0` only knows up to 2.4. `v1.14.2` ships
Twine 7, which accepts 2.5 (pypa/gh-action-pypi-publish#416).

No repo code caused this — it is floating-dependency drift, which is why
1.2.1 published fine on the identical workflow.

**Follow-up needed:** 1.3.0 is still not on PyPI (latest is 1.2.1). Once
this merges, the `v1.3.0` tag has to be moved to the fixed commit (or
re-created) to re-trigger the publish job.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
mjbommar added a commit to 273v/kaos-web that referenced this pull request Sep 21, 2026
…64)

The v0.1.15 publish failed at the upload step:

    InvalidDistribution: Invalid distribution metadata:
    '2.5' is not a valid metadata version

hatchling now emits Metadata-Version: 2.5, and the pinned action was
v1.14.1, whose bundled Twine predates 2.5 support. v1.14.2 exists
precisely for this -- its release notes call out the Twine v7 bump
"to let them upload their sdists and wheels containing core packaging
metadata v2.5 to (Test)PyPI" (pypa/gh-action-pypi-publish#416).

Local `twine check --strict` did not catch it because `uvx --from twine`
resolves current Twine, which accepts 2.5. Only the action's pinned,
older copy rejected it, so the gate was green everywhere except the one
place that mattered.

Nothing was published: PyPI is still at 0.1.14 and the 0.1.15 upload was
rejected before any file was accepted. The v0.1.15 tag and its GitHub
release (wheel, sdist, SBOM) were created and are untouched.

Signed-off-by: Mike Bommarito <michael.bommarito@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants