Ensure Sigstore CLI on downloads server is >= 3.6.2 and < 4 #293
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
During the 3.15.0a1 release, after the release files had been signed by Sigstore I got this error during the verification:
This was fixed in Sigstore 3.6.2: sigstore/sigstore-python#1350
I upgraded my version of
sigstoreon the downloads server from 3.5.3 to 3.6.6 (the latest 3.6.x, and the latest 3.x that's <4) and it then worked.So let's adjust the "Checking Sigstore CLI" pre-check which runs at the start of the whole release, so instead of checking
>=3, it checks>= 3.6.2and<4.This original
>=3check was added in #194.We also have a second
sigstoreversion check later on.It's part of
add_to_pydotorg.py, which runs on the downloads server, and does the actual signing/verifying/uploading.This was added in #167.
I didn't change this to also check
>= 3.62, < 4. In fact, I think we could remove it because we have the pre-check above?