shahar1 opened a new pull request, #73887:
URL: https://github.com/apache/airflow/pull/73887

   PyPI never allows a filename to be reused, even after the file, its release 
or its whole project was deleted. It also hides deleted files everywhere except 
its public BigQuery dataset. The PyPI project page, the JSON API and the 
project's security history don't show them.
   
   The DuckDB provider hit this in the 2026-09-22 wave. Its 0.1.0 upload failed 
after the vote had passed, because an earlier, deleted project with the same 
name had uploaded 0.1.0 and 0.1.1 in 2025. The provider had to be excluded from 
the wave.
   
   This adds a step before the wave starts, for every provider being released 
for the first time:
   
   - Query the public BigQuery dataset for the name's upload history, and 
compare it with what PyPI lists now. A single query processes about 2 GB, which 
is within the free tier. Release managers without a Google Cloud account ask 
another release manager to run it.
   - If deleted versions exist, start from the next minor version after the 
highest deleted `0.X.Y`, or the next major version after a deleted `1.X.Y` or 
higher.
   - Add a changelog warning that the deleted versions were not community 
releases.
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code (Opus 5.5)
   
   Generated-by: Claude Code (Opus 5.5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to