Skip to content

v5: drop PyPI and RubyGems distributions - #298

Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
release/v5-prereleasefrom
v5/simplify-distributions
Sep 30, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 1 commit into
release/v5-prereleasefrom
v5/simplify-distributions

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Targets release/v5-prerelease (#277).

v5 now ships through three distributions: standalone binaries via install.socket.dev/patch (preferred), Cargo crates, and npm. npm remains available for the official Socket CLI. This removes the maintenance burden of publishing Python and Ruby wrappers while preserving Python and Ruby dependency patching and its compatibility coverage.

  • Delete the PyPI CLI and startup-hook packages, RubyGems launcher and Bundler plugin, and wheel builder.
  • Remove their publish workflows, release fan-out jobs, package-specific CI checks, and version-sync entries. Keep binary builds and Cargo/npm publishing intact.
  • Simplify README installation instructions and update the release runbook, CLI contract, v5 plan, and changelog. Include migration guidance for existing pip/pipx/gem installations and install hooks.
  • Keep the updater's protection for legacy package-owned paths, but replace pip/gem upgrade hints with migration commands to the binary installer (macOS/Linux) or npm (Windows).

Validation

  • Core install-channel tests: 15 passed; CLI update-channel integration tests: 9 passed.
  • npm platform dispatch tests: 4 passed; Python CI/installer harness tests: 125 run, 1 skipped, no failures.
  • scripts/release-lint.sh --sync-only passed. In a temporary checkout, scripts/bump-version.sh 5.0.0 synchronized Cargo, all 15 npm packages, the npm lockfile, and release notes; the full scripts/release-lint.sh 5.0.0 gate passed.
  • Standalone installer smoke test passed in a temporary directory using the current published release (4.0.0); the hosted script matches scripts/install.sh byte for byte.
  • ShellCheck, formatting checks for touched Rust files, git diff --check, and actionlint for release/publish/version-bump workflows passed.

ci.yml has 45 existing actionlint matrix-property diagnostics on the v5 base. Comparing diagnostics before and after this change found no additions.


Note

Medium Risk
Large removal of publish paths and install channels affects every release and existing pip/gem users, though behavior is documented and covered by updated channel/migration tests.

Overview
v5 narrows how the CLI is shipped: standalone binaries (install.socket.dev/patch), Cargo, and npm only. PyPI wheels, RubyGems launcher/bundler gems, their sources, tests, build-pypi-wheels.py, and publish-pypi.yml / publish-rubygems.yml are removed.

Release and CI now fan out only to crates.io and npm (release.yml drops pypi-publish / rubygems-publish jobs). version-sync.sh, release-lint, and bump scripts no longer touch Python/Ruby packaging. CI drops Ruby gem syntax checks and PyPI dispatch tests; ecosystem lint focuses on the installer and Python harness tests.

User-facing docs (README, CHANGELOG, releasing runbook, CLI contract) promote the curl installer and add migration steps for pip/gem users and old install hooks.

Self-update still detects legacy site-packages and gem launcher cache paths but refuses in-place updates and prints uninstall + standalone installer (Unix) or global npm (Windows) instead of pip install --upgrade / gem update.

Reviewed by Cursor Bugbot for commit bd40e28. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant