Skip to content

Commit 5e9ce62

Browse files
committed
ci: switch release to pypi trusted publishing (oidc)
1 parent 22c6326 commit 5e9ce62

1 file changed

Lines changed: 20 additions & 18 deletions

File tree

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,39 +1,41 @@
1-
# Release workflow. Filename and environment name are load-bearing:
2-
# the PyPI trusted publisher (OIDC) configuration references
3-
# workflow "on-release-main.yml" and environment "pypi".
1+
# Release workflow: publishes to PyPI via OIDC trusted publishing.
42
#
5-
# INTERIM STATE during the repo migration: publishing still uses the
6-
# PYPI_TOKEN secret via twine. The release phase of the migration
7-
# replaces it with `uv publish --trusted-publishing always` (OIDC)
8-
# and adds the docs deployment job.
3+
# Filename and environment name are load-bearing: the trusted publisher
4+
# configured on PyPI references workflow "on-release-main.yml" and
5+
# environment "pypi" (no token/secret involved).
6+
#
7+
# Docs are deployed from main by docs.yml; the docs-versioning phase of
8+
# the migration adds the per-release docs deploy (mike) to this workflow.
99

1010
name: release-main
1111

1212
on:
1313
push:
1414
tags: ['v[0-9]*']
15-
workflow_dispatch: # Allow manually triggering the workflow
1615

1716
jobs:
1817
publish:
19-
if: ${{ github.event_name == 'push' && contains(github.ref, 'refs/tags/') }}
2018
runs-on: ubuntu-latest
2119
environment:
2220
name: pypi
21+
permissions:
22+
contents: read
23+
# required for PyPI trusted publishing (OIDC)
24+
id-token: write
2325
steps:
2426
- uses: actions/checkout@v4
2527
with:
26-
# deep clone incl. tags so hatch-vcs can derive the version
28+
# deep clone incl. tags so hatch-vcs derives the version from the tag
2729
fetch-depth: 0
30+
2831
- name: Set up the environment
2932
uses: ./.github/actions/setup-python-env
33+
3034
- name: Build package distribution files
3135
run: uv build
32-
- name: Publish Package
33-
env:
34-
TWINE_REPOSITORY: pypi
35-
TWINE_USERNAME: __token__
36-
TWINE_PASSWORD: ${{ secrets.PYPI_TOKEN }}
37-
run: |
38-
uvx twine check dist/*
39-
uvx twine upload dist/*
36+
37+
- name: Check package metadata
38+
run: uvx twine check dist/*
39+
40+
- name: Publish package
41+
run: uv publish --trusted-publishing always

0 commit comments

Comments
 (0)