Skip to main content

Check the contents of an SDist vs. git

Project description

check-sdist

Actions Status codecov PyPI version PyPI platforms

Have you ever shipped broken SDists with missing files or possibly dirty SDists with files that shouldn't have been there? Have you noticed that standards compliant tools aren't making the same SDist that flit build is? Is hatchling adding .DSStore files when you ship from your macOS? No matter what build-backend you use, check-sdist can help!

Check-sdist builds an SDist and compares the contents with your Git repository contents. It can even temporarily inject common junk files (like pycache files or OS specific files) and help verify that those aren't getting bundled into your SDist. If you are getting files you didn't expect or missing files you did expect, consult your build backend's docs to see how to include or exclude files.

Quick start

To run with pipx:

$ pipx run check-sdist[uv]

Or, if you like uv instead (faster):

$ uvx check-sdist

You can add --no-isolation to disable build isolation (faster, but must preinstall build dependencies), --source-dir to select a different source directory to check, and --inject-junk to temporarily inject some common junk files while running. You can select an installer for build to use with --installer=, choices are uv, pip, or uv|pip, which will use uv if available (the default).

If you need the latest development version:

$ pipx run --spec git+https://github.com/henryiii/check-sdist check-sdist

Pre-commit integration

To use the pre-commit integration, put this in your .pre-commit-config.yaml:

- repo: https://github.com/henryiii/check-sdist
  rev: v1.2.0
  hooks:
    - id: check-sdist
      args: [--inject-junk]
      additional_dependencies: [] # list your build deps here

This requires your build dependencies, but in doing so, it can cache the environment, making it quite fast. The installation is handled by pre-commit; see pre-commit-uv if you want to try to optimize the initial setup. If uv is present (including in your additional_dependencies), the build will be slightly faster, as uv is used to do the build. If you don't mind slower runs and don't want to require a build dependency listing:

- repo: https://github.com/henryiii/check-sdist
  rev: v1.2.0
  hooks:
    - id: check-sdist-isolated
      args: [--inject-junk]

This one defaults to including uv in additional_dependencies; you shouldn't have to specify anything else.

Configuration

To configure, these options are supported in your pyproject.toml file:

[tool.check-sdist]
sdist-only = []
git-only = []
default-ignore = true
recurse-submodules = true
mode = "git"
build-backend = "auto"

You can add .gitignore style lines here, and you can turn off the default ignore list, which adds some default git-only files.

By default, check-sdist recursively scans the contents of Git submodules, but you can disable this behavior (e.g. to support older Git versions that don't have this capability).

You can also select mode = "all", which will instead check every file on your system. Be prepared to ignore lots of things manually, like *.pyc files, if you use this.

You can tell check-sdist to look for exclude lists for a specific build backend with build-backend, or "none" to only use it's own exclude list. Build backends supported are "flit_core.buildapi", "hatchling.build", "scikit_build_core.build", "pdm.backend", "maturin", and "poetry.core.masonry.api". The default, "auto", will try to detect the build backend if build-system.build-backend is set to a known value.

See also

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

check_sdist-1.2.0.tar.gz (16.9 kB view details)

Uploaded Source

Built Distribution

check_sdist-1.2.0-py3-none-any.whl (13.3 kB view details)

Uploaded Python 3

File details

Details for the file check_sdist-1.2.0.tar.gz.

File metadata

  • Download URL: check_sdist-1.2.0.tar.gz
  • Upload date:
  • Size: 16.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for check_sdist-1.2.0.tar.gz
Algorithm Hash digest
SHA256 7b74d61590768b90f233e61b11183ca910cac27c1818e11e981b2ef13843f741
MD5 0cbda0e9a82635d3bb3d56c00b3db7dd
BLAKE2b-256 6270736a14df53b496dc7e2edfd1c4e45babd5506c8c93c77053b25eff3ffcdb

See more details on using hashes here.

Provenance

The following attestation bundles were made for check_sdist-1.2.0.tar.gz:

Publisher: cd.yml on henryiii/check-sdist

Attestations:

File details

Details for the file check_sdist-1.2.0-py3-none-any.whl.

File metadata

  • Download URL: check_sdist-1.2.0-py3-none-any.whl
  • Upload date:
  • Size: 13.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for check_sdist-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8b3f4630cec288a3dd6e91b661910e8fe689d6e8767f7162483d33857c59fb37
MD5 19be3afa0c209beef7f5491cfb3639eb
BLAKE2b-256 e99ef59f3a9331be078b8fac853fdf6c0ced7cd623d3df8c319b9ce92ced651a

See more details on using hashes here.

Provenance

The following attestation bundles were made for check_sdist-1.2.0-py3-none-any.whl:

Publisher: cd.yml on henryiii/check-sdist

Attestations:

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page