[main-red] molecule-ai/molecule-core: ec664869b0 #1383

Closed
opened 2026-05-16 22:07:30 +00:00 by gitea-actions · 1 comment

[triage-operator] main-red-watchdog PASSED at 05:05Z on main HEAD c3cfbea750. All main-red issues resolved. Closing.

[triage-operator] main-red-watchdog PASSED at 05:05Z on main HEAD c3cfbea750df. All main-red issues resolved. Closing.
gitea-actions bot added the tier:high label 2026-05-16 22:07:30 +00:00
Owner

needs-hongming: PyPI publish is blocked by a credential/project-scope 403, not by a build/test failure.

Fresh evidence from 15:24 PDT triage:

  • Latest publish-runtime / publish (push) for ec664869b09a failed again on run 60423/jobs/0 after 2m11s; cascade skipped.
  • Direct log from prior run 60369/jobs/0 shows build, twine check, wheel install smoke, AgentCard smoke, mount alignment smoke, and helper import smoke all passed for molecule_ai_workspace_runtime-0.1.1001.
  • Upload then failed at PyPI: HTTPError: 403 Forbidden from https://upload.pypi.org/legacy/ while uploading molecule_ai_workspace_runtime-0.1.1001-py3-none-any.whl; PYPI_TOKEN was present/masked, so this is not a missing-secret failure.
  • PyPI live readback: molecule-ai-workspace-runtime latest is 0.1.1000, and release 0.1.1001 does not exist, so this is not a duplicate-file/version collision.

Impact: runtime publish and downstream cascade are blocked on main; repeated reruns will keep red until the PyPI token/project permission is fixed.

Question for Hongming: can you rotate or replace the Gitea PYPI_TOKEN secret for molecule-core so it has upload permission for the molecule-ai-workspace-runtime PyPI project? I did not rotate secrets or edit repo secrets.

needs-hongming: PyPI publish is blocked by a credential/project-scope 403, not by a build/test failure. Fresh evidence from 15:24 PDT triage: - Latest `publish-runtime / publish (push)` for `ec664869b09a` failed again on run `60423/jobs/0` after 2m11s; cascade skipped. - Direct log from prior run `60369/jobs/0` shows build, `twine check`, wheel install smoke, AgentCard smoke, mount alignment smoke, and helper import smoke all passed for `molecule_ai_workspace_runtime-0.1.1001`. - Upload then failed at PyPI: `HTTPError: 403 Forbidden from https://upload.pypi.org/legacy/` while uploading `molecule_ai_workspace_runtime-0.1.1001-py3-none-any.whl`; `PYPI_TOKEN` was present/masked, so this is not a missing-secret failure. - PyPI live readback: `molecule-ai-workspace-runtime` latest is `0.1.1000`, and release `0.1.1001` does not exist, so this is not a duplicate-file/version collision. Impact: runtime publish and downstream cascade are blocked on main; repeated reruns will keep red until the PyPI token/project permission is fixed. Question for Hongming: can you rotate or replace the Gitea `PYPI_TOKEN` secret for `molecule-core` so it has upload permission for the `molecule-ai-workspace-runtime` PyPI project? I did not rotate secrets or edit repo secrets.
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: molecule-ai/molecule-core#1383