On Sun, Sep 27, 2026 at 2:26 AM Nathan via NumPy-Discussion <
[email protected]> wrote:

>
>
> On Sat, Sep 26, 2026 at 5:11 PM Charles R Harris via NumPy-Discussion <
> [email protected]> wrote:
>
>> Hi All,
>>
>> I am thinking we should simplify our releases on GitHub. Currently I post
>> release notes, translated from rst to gpm, and upload a source file, a
>> changelog, and the release notes in rst. I am thinking that all we really
>> need to do is post the release notes,
>>
>
> Does this mean just a link? If so I agree and I think it’s a good idea to
> minimize reliance on GitHub if we can avoid it.
>

+1 from me as well. Now that we have trusted publishing, there is a
provenance link for released sdist and wheels. Having a manual download and
re-upload to GitHub without provenance tracing is not useful, and carries a
chance of hard to detect mistakes.

SciPy already made the same change in 1.18.0

Cheers,
Ralf



>
>
> with a footer warning not to use the GitHub generated release products,
>> and an admonition to download from PyPI. That leaves no security holes for
>> the source, and the changelog can be accessed on GitHub itself.
>>
>> Thoughts?
>>
>> Chuck
>> _______________________________________________
>> NumPy-Discussion mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>> https://mail.python.org/mailman3//lists/numpy-discussion.python.org
>> Member address: [email protected]
>>
> _______________________________________________
> NumPy-Discussion mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> https://mail.python.org/mailman3//lists/numpy-discussion.python.org
> Member address: [email protected]
>
_______________________________________________
NumPy-Discussion mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/numpy-discussion.python.org
Member address: [email protected]

Reply via email to