twine-venv: pin twine<6 — classic ~/.pypirc auth on build runner

twine 6 (Sep 2025) auto-detects GitLab CI and refuses to fall back to
~/.pypirc, requiring PYPI_ID_TOKEN (Trusted Publishing OIDC). Pin <6
to keep the runner's ~/.pypirc fallback working until we migrate all
python/* repos to Trusted Publishing as a coordinated change.
This commit is contained in:
russell@unturf.com 2026-06-16 14:12:00 -04:00
parent 892e6a859e
commit 3053704247
No known key found for this signature in database

View file

@ -173,7 +173,12 @@ TWINE = $(TWINE_VENV)/bin/twine
$(TWINE_VENV)/bin/twine:
@echo "Creating twine virtualenv in $(TWINE_VENV)..."
python3 -m venv $(TWINE_VENV)
$(TWINE_VENV)/bin/pip install --upgrade pip twine
# Pin twine <6 — newer twine auto-detects GitLab CI and refuses to
# fall back to ~/.pypirc on the runner, requiring PYPI_ID_TOKEN
# (Trusted Publishing OIDC). Until we migrate to Trusted Publishing,
# stick with classic ~/.pypirc auth on the build runner.
$(TWINE_VENV)/bin/pip install --upgrade pip
$(TWINE_VENV)/bin/pip install "twine<6"
twine-venv: $(TWINE_VENV)/bin/twine