PyPI Publishing

pyproject.toml is the canonical release-version source. The private frontend package and its lock file carry the same version so a release commit identifies one application build. Update all three files in the release commit; do not use the frontend package version as an independent release stream.

The make package workflow builds the frontend and Sphinx documentation before creating the wheel and source distribution. Generated frontend files are owned by staticfiles/; generated documentation is owned by static/docs/ for the deployed documentation route. docs/_build/ is disposable local build output and is not committed.

Updating the frontend dependency hash

A commit might add a package to package.json and package-lock.json while the Nix expression still contains the hash for the previous dependency set:

npmDepsHash = "sha256-gFyVehSwVatoPJnel6OSbV2mYRbG3Fbk5/aooeEzzhw=";

Nix downloaded the dependencies described by the new lockfile, calculated their actual hash, and correctly rejected them because reproducibility checks found:

expected: sha256-gFyVehSwVatoPJnel6OSbV2mYRbG3Fbk5/aooeEzzhw=
actual:   sha256-w4+drE6pSUWLrKiGetBqttaomC9mPEMDwm8ElcpLoVY=

Update npmDepsHash to the reported actual hash and rerun make package:

npmDepsHash = "sha256-w4+drE6pSUWLrKiGetBqttaomC9mPEMDwm8ElcpLoVY=";