Skip to content

v0.5.3 — Release Pipeline Repair (first published 0.5.2 security line)

Latest

Choose a tag to compare

@Julio-Patron Julio-Patron released this 26 Sep 10:53
1358831

First published build of the 0.5.2 security line.

The v0.5.2 release workflow failed before building any artifact, so 0.5.2 was never published to PyPI or crates.io. 0.5.3 ships the same runtime code (all 0.5.2 security remediations: delegation chain verification, signed policy activation, segregation of duties, Gate-DB revocation checks for executors, atomic state/stream mutations) with a repaired release pipeline.

Fixed

  • Release pipeline: four action pins in release.yml referenced commit SHAs that don't exist upstream. All pins now resolve to real tags.
  • Tag-exact builds: each release job checks out the release tag.
  • PyPI: publishes through Trusted Publishing (OIDC) only.
  • crates.io: first publication, from a separate job that uses the configured token.

Changed

  • Packaged sources no longer include the launch/ drafts.
  • python-dotenv>=1.2.3.

Install: python -m pip install tempus-ddb==0.5.3

Full details in CHANGELOG.md.