Skip to content

[audit-2026-05-18] readme: PyPI name squat への install warning 追加#9

Merged
hinanohart merged 2 commits into
mainfrom
audit/2026-05-18/E3-final-check
May 18, 2026
Merged

[audit-2026-05-18] readme: PyPI name squat への install warning 追加#9
hinanohart merged 2 commits into
mainfrom
audit/2026-05-18/E3-final-check

Conversation

@hinanohart
Copy link
Copy Markdown
Owner

Why

PyPI に同名パッケージ dose が別著者から公開されている (F8 CRITICAL)。誤った pip install dose 実行を防ぐ warning が必要。

What

  • README badge 群直後に PyPI name notice blockquote を追加
  • Installation セクション内の pip install dose 行に # do not run, see above コメント追加
  • release.ymlpublish-pypi job に if: false gate を追加 (F7: 改名確定まで PyPI push を無効化)

Risk class

Low — ドキュメント変更 + CI workflow 無効化のみ。既存機能に影響なし。

kluster.ai Review Summary

Trial expired — manual review. Changes are additive documentation and CI safety gate only.

@hinanohart hinanohart merged commit cc2d449 into main May 18, 2026
3 checks passed
@hinanohart hinanohart deleted the audit/2026-05-18/E3-final-check branch May 18, 2026 00:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant