Merge pull request #114 from OO-LD/feat/validator-migration #9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release-main | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| inputs: | |
| force: | |
| description: > | |
| Cut a release even when the commits since the last tag do not warrant | |
| one. Use this to recover when a release was tagged but the publish | |
| step failed, since python-semantic-release will not re-cut an | |
| existing tag. | |
| type: choice | |
| options: [none, patch, minor] | |
| default: none | |
| concurrency: | |
| group: release | |
| cancel-in-progress: false | |
| jobs: | |
| release: | |
| runs-on: ubuntu-latest | |
| # PyPI's trusted publisher for this project is registered with the | |
| # environment name "pypi", so the OIDC token must carry that claim. | |
| # Without it PyPI rejects the upload with 422 invalid-publisher, which is | |
| # why 0.16.3 and 0.16.4 were tagged but never published. | |
| environment: pypi | |
| permissions: | |
| id-token: write # OIDC trusted publishing to PyPI | |
| contents: write # push the release commit and tag, create the GitHub release | |
| outputs: | |
| released: ${{ steps.version.outputs.released }} | |
| version: ${{ steps.version.outputs.version }} | |
| steps: | |
| - name: Generate app token | |
| id: app-token | |
| uses: actions/create-github-app-token@v1 | |
| with: | |
| app-id: ${{ secrets.RELEASE_APP_ID }} | |
| private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} | |
| - name: Check out | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 # full history + tags so PSR can analyze commits | |
| ref: main | |
| token: ${{ steps.app-token.outputs.token }} # app identity bypasses the main ruleset | |
| - name: Set up the environment | |
| uses: ./.github/actions/setup-python-env | |
| - name: Configure git identity | |
| run: | | |
| git config user.name "github-actions[bot]" | |
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
| - name: Semantic release version | |
| id: version | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| FORCE: ${{ inputs.force || 'none' }} | |
| run: | | |
| before=$(git rev-parse HEAD) | |
| # PSR bumps files, updates CHANGELOG.md, commits and tags, but does not | |
| # create the GitHub release; we create it below with GitHub's generated | |
| # "What's Changed" notes so Zenodo shows them (no changelog duplication). | |
| if [ "$FORCE" = "none" ]; then | |
| uv run semantic-release version --no-vcs-release | |
| else | |
| uv run semantic-release version --no-vcs-release "--$FORCE" | |
| fi | |
| after=$(git rev-parse HEAD) | |
| if [ "$before" != "$after" ]; then | |
| tag=$(git tag --points-at HEAD | grep -E '^v[0-9]' | head -1) | |
| echo "released=true" >> "$GITHUB_OUTPUT" | |
| echo "version=${tag#v}" >> "$GITHUB_OUTPUT" | |
| echo "Released $tag" | |
| else | |
| echo "released=false" >> "$GITHUB_OUTPUT" | |
| echo "No release for this push." | |
| fi | |
| - name: Build package | |
| if: steps.version.outputs.released == 'true' | |
| run: uv build | |
| - name: Check package metadata | |
| if: steps.version.outputs.released == 'true' | |
| run: uvx twine check dist/* | |
| - name: Publish to PyPI (OIDC trusted publishing) | |
| if: steps.version.outputs.released == 'true' | |
| run: uv publish --trusted-publishing always | |
| - name: Create GitHub release with generated notes | |
| if: steps.version.outputs.released == 'true' | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| VERSION: ${{ steps.version.outputs.version }} | |
| run: | | |
| gh release create "v$VERSION" --verify-tag --title "v$VERSION" --generate-notes | |
| # Append a link to the full grouped changelog (kept in CHANGELOG.md), | |
| # so the release has "What's Changed" plus a pointer, no duplication. | |
| notes=$(gh release view "v$VERSION" --json body -q .body) | |
| link="Full grouped changelog: [CHANGELOG.md](https://github.com/${GITHUB_REPOSITORY}/blob/v${VERSION}/CHANGELOG.md)" | |
| gh release edit "v$VERSION" --notes "${notes}"$'\n\n---\n'"${link}" | |
| deploy-docs: | |
| needs: release | |
| if: needs.release.outputs.released == 'true' | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check out | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: main # include the release commit just pushed by PSR | |
| - name: Set up the environment | |
| uses: ./.github/actions/setup-python-env | |
| - name: Build documentation | |
| run: uv run zensical build --clean | |
| - name: Upload artifact | |
| uses: actions/upload-pages-artifact@v4 | |
| with: | |
| path: site | |
| - name: Deploy to GitHub Pages | |
| id: deployment | |
| uses: actions/deploy-pages@v4 |