|
1 | | -# Release workflow. Filename and environment name are load-bearing: |
2 | | -# the PyPI trusted publisher (OIDC) configuration references |
3 | | -# workflow "on-release-main.yml" and environment "pypi". |
| 1 | +# Release workflow: publishes to PyPI via OIDC trusted publishing. |
4 | 2 | # |
5 | | -# INTERIM STATE during the repo migration: publishing still uses the |
6 | | -# PYPI_TOKEN secret via twine. The release phase of the migration |
7 | | -# replaces it with `uv publish --trusted-publishing always` (OIDC) |
8 | | -# and adds the docs deployment job. |
| 3 | +# Filename and environment name are load-bearing: the trusted publisher |
| 4 | +# configured on PyPI references workflow "on-release-main.yml" and |
| 5 | +# environment "pypi" (no token/secret involved). |
| 6 | +# |
| 7 | +# Docs are deployed from main by docs.yml; the docs-versioning phase of |
| 8 | +# the migration adds the per-release docs deploy (mike) to this workflow. |
9 | 9 |
|
10 | 10 | name: release-main |
11 | 11 |
|
12 | 12 | on: |
13 | 13 | push: |
14 | 14 | tags: ['v[0-9]*'] |
15 | | - workflow_dispatch: # Allow manually triggering the workflow |
16 | 15 |
|
17 | 16 | jobs: |
18 | 17 | publish: |
19 | | - if: ${{ github.event_name == 'push' && contains(github.ref, 'refs/tags/') }} |
20 | 18 | runs-on: ubuntu-latest |
21 | 19 | environment: |
22 | 20 | name: pypi |
| 21 | + permissions: |
| 22 | + contents: read |
| 23 | + # required for PyPI trusted publishing (OIDC) |
| 24 | + id-token: write |
23 | 25 | steps: |
24 | 26 | - uses: actions/checkout@v4 |
25 | 27 | with: |
26 | | - # deep clone incl. tags so hatch-vcs can derive the version |
| 28 | + # deep clone incl. tags so hatch-vcs derives the version from the tag |
27 | 29 | fetch-depth: 0 |
| 30 | + |
28 | 31 | - name: Set up the environment |
29 | 32 | uses: ./.github/actions/setup-python-env |
| 33 | + |
30 | 34 | - name: Build package distribution files |
31 | 35 | run: uv build |
32 | | - - name: Publish Package |
33 | | - env: |
34 | | - TWINE_REPOSITORY: pypi |
35 | | - TWINE_USERNAME: __token__ |
36 | | - TWINE_PASSWORD: ${{ secrets.PYPI_TOKEN }} |
37 | | - run: | |
38 | | - uvx twine check dist/* |
39 | | - uvx twine upload dist/* |
| 36 | + |
| 37 | + - name: Check package metadata |
| 38 | + run: uvx twine check dist/* |
| 39 | + |
| 40 | + - name: Publish package |
| 41 | + run: uv publish --trusted-publishing always |
0 commit comments